
Configuration Examples
308630-14.00 Rev 00
C-21
• Packet capture: Run packet capture on the interface on which IPsec is
configured (or on other interfaces where traffic originates or is destined out
of). Although encrypted packets are still encrypted as viewed through packet
capture, you can tell which are IKE and which are IPsec packets and get an
idea of how far an SA negotiation gets in the process of establishing IKE and
IPsec SAs.
Contivity Tools
Contivity provides the following troubleshooting tools that may help with
interoperability issues:
• Manager Status > Event Log displays. Config, System, and Security Log
displays may also be helpful.
• Manager Status > Sessions display lets you see details on the sessions (IPsec
tunnels) for each running Branch Office Connection. These details include the
time each session is expected to expire.
• Manager Status > Statistics display.
Symptoms You May See
If traffic does not appear to traverse the IPsec tunnel, first check for configuration
mismatches such as the following:
• PFS is enabled on Contivity but not enabled on BayRS for every policy with a
proposal with the Contivity switch as the destination gateway.
Sample Contivity event log message:
09/02/1999 23:15:53 0 ISAKMP [03] PFS required but not provided
by 144.1.1.152
Comentários a estes Manuais