
Configuring IPsec Services
D-6
308630-15.1 Rev 00
Troubleshooting BayRS-Contivity IPsec Interoperability
Use the following troubleshooting tools to diagnose and resolve interoperability
problems between the BayRS and Contivity implementations of IPsec.
BayRS Tools
BayRS provides the following troubleshooting tools that may help with
interoperability issues:
• Event log—Look for IPsec, IKE, IPsec_Audit, and KEYMGR events.
• Technician Interface show scripts—Use Technician Interface show scripts to
display information and statistics about IPsec and IKE policies and SAs. For
example,
show ipsec selector out
displays how many packets matched each
policy.
• Technician Interface—Enable IPsec debugging using the Technician Interface
command
ipsec
. Enter
help ipsec
for command usage.
• Packet capture—Run packet capture on the interface on which IPsec is
configured (or on other interfaces where traffic originates or exits). Although
encrypted packets are still encrypted when viewed through packet capture,
you can distinguish IKE packets from IPsec packets and get an idea of how far
an SA negotiation gets in the process of establishing IKE and IPsec SAs.
Contivity Tools
Contivity software provides the following troubleshooting tools that may help
with interoperability issues:
• The Admin > Status > Event Log display provides a detailed record of all
events that take place on the system.
• The Test button on the Profiles > Branch Office display allows you to verify
that the branch office connection is properly configured and that the remote
gateway remains reachable. Detailed messages are sent to the event log.
• The Admin > Status > Sessions display provides details of the sessions (IPsec
tunnels) for each active branch office connection. These details include the
time that each session is expected to expire.
• The Admin > Status > Statistics display provides system-level statistics that
can help resolve lower-level problems with connections.
Komentarze do niniejszej Instrukcji