
Appendix B Log Descriptions 445
Nortel Business Secure Router 252 Configuration — Basics
Table 133 shows sample log messages during packet transmission.
-> <symbol> The router sent a payload type of IKE packet.
Error ID Info The parameters configured for Phase 1 ID content
do not match or the parameters configured for the
Phase 2 ID (IP address of single, range, or subnet)
do not match. Check all protocols and settings for
these phases.
Table 133 Sample IPSec Logs During Packet Transmission
LOG MESSAGE DESCRIPTION
!! WAN IP changed to <IP> If the Business Secure Router WAN IP changes,
all configured My IP Addr change to 0.0.0.0. If
this field is configured as 0.0.0.0, the Business
Secure Router uses the current Business
Secure Router WAN IP address (static or
dynamic) to set up the VPN tunnel.
!! Cannot find IPSec SA The Business Secure Router cannot find a
phase 2 SA that corresponds with the SPI of an
inbound packet (from the peer); the packet is
dropped.
!! Cannot find outbound SA
for rule <%d>
The packet matches the rule index number (#d),
but Phase 1 or Phase 2 negotiation for outbound
(from the VPN initiator) traffic is not finished yet.
!! Discard REPLAY packet The Business Secure Router discards any
packets received with the wrong sequence
number.
!! Inbound packet
authentication failed
The authentication configuration settings are
incorrect. Check them.
!! Inbound packet decryption
failed
The decryption configuration settings are
incorrect. Check them.
Rule <#d> idle time out,
disconnect
If an SA has no packets transmitted for a period
of time (configurable through CI command), the
Business Secure Router drops the connection.
Table 132 Sample IKE Key Exchange Logs
Log Message Description
Comentários a estes Manuais