
Appendix B Log Descriptions 443
Nortel Business Secure Router 252 Configuration — Basics
Table 132 Sample IKE Key Exchange Logs
Log Message Description
Send <Symbol> Mode
request to <IP>Send
<Symbol> Mode request to
<IP>
The Business Secure Router started negotiation with
the peer.
Recv <Symbol> Mode
request from <IP>Recv
<Symbol> Mode request
from <IP>
The Business Secure Router received an IKE
negotiation request from the peer.
Recv:<Symbol> IKE uses the ISAKMP protocol (refer to RFC 2408 –
ISAKMP) to transmit data. Each ISAKMP packet
contains payloads of different types that show in the
log (see Table 134).
Phase 1 IKE SA process
done
Phase 1 negotiation finished.
Start Phase 2: Quick Mode Phase 2 negotiation begins using Quick Mode.
!! IKE Negotiation is in
process
The Business Secure Router has begun negotiation
with the peer for the connection, but the IKE key
exchange has not completed.
!! Duplicate requests
with the same cookie
The Business Secure Router received multiple
requests from the same peer but is still processing
the first IKE packet from that peer.
!! No proposal chosen The parameters configured for Phase 1 or Phase 2
negotiations do not match. Check all protocols and
settings for these phases. For example, one party
uses 3DES encryption, but the other party uses DES
encryption, so the connection fails.
!! Verifying Local ID
failed!! Verifying Remote
ID failed
During IKE Phase 2 negotiation, both parties
exchange policy details, including local and remote
IP address ranges. If these ranges differ, the
connection fails.
!! Local / remote IPs of
incoming request conflict
with rule <#d>
If the security gateway is “0.0.0.0”, the Business
Secure Router uses the peer “Local Addr” as its
“Remote Addr”. If this IP (range) conflicts with a
previously configured rule, the connection is not
allowed.
!! Invalid IP <IP start>/
<IP end>
The peer “Local IP Addr” range is invalid.
Komentarze do niniejszej Instrukcji