Appendix A Log Descriptions

Table 247 IKE Logs (continued)

LOG MESSAGE

DESCRIPTION

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the DH

Phase 1 key group

group of the attribute list `attrs' did not match the security

mismatch

policy.

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-1, the

Phase 1 negotiation

negotiation mode did not match.

mode mismatch

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the

Phase 2 authentication

authentication algorithm did not match.

algorithm mismatch

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the

Phase 2 encapsulation

encapsulation did not match.

mismatch

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the

Phase 2 encryption

encryption algorithm did not match.

algorithm mismatch

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the PFS

Phase 2 pfs mismatch

specified did not match.

[SA] : Tunnel [%s]

%s is the tunnel name.When negotiating Phase-2, this device

Phase 2 pfs

does not support the PFS specified.

unsupported: %d

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the SA

Phase 2 SA

encapsulation did not match.

encapsulation

 

mismatch

 

[SA] : Tunnel [%s]

%s is the tunnel name. When negotiating Phase-2, the SA

Phase 2 SA protocol

protocol did not match.

mismatch

 

[SA] : Tunnel [%s] SA

%s is the tunnel name. When negotiating Phase-2, the SA

sequence size mismatch

sequence size did not match.

[XCHG] exchange type

This device is the responder and this is the initiator’s first

is not IP, AGGR, or

packet, but exchange type is not IP, AGGR, or INFO and the

INFO

packet is ignored.

Cannot resolve My IP

1st %s is my ip address. 2nd %s is the tunnel name. When

Addr %s for Tunnel

selecting a matched proposal in phase-1, the engine could not

[%s]

get My-IP address.

Cannot resolve Secure

1st %s is my ip address. 2nd %s is the tunnel name; When

Gateway Addr %s for

selecting a matched proposal in phase-1, the engine could not

Tunnel [%s]

get the correct secure gateway address.

Could not dial dynamic

%s is the tunnel name. The tunnel is a dynamic tunnel and

tunnel "%s"

the device cannot dial it.

Could not dial

%s is the tunnel name. The tunnel setting is not complete.

incomplete tunnel "%s"

 

Could not dial manual

%s is the tunnel name. The manual key tunnel cannot be

key tunnel "%s"

dialed.

DPD response with

When receiving a DPD response with invalid ID ignored.

invalid ID

 

DPD response with no

When receiving a DPD response with no active query.

active request

 

764

 

ZyWALL USG 20/20W User’s Guide