VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 143

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 142
VMware, Inc. 143
Appendix B vShield Edge VPN Configuration Examples
Phase 2 Not Matching
vShield Edge
vShieldEdgehangsatSTATE_QUICK_I1.AlogmessageshowsthatthepeersentaNO_PROPOSAL_CHOSEN
message.
000 #2: "s1-c1":500 STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in 11s;
lastdpd=-1s(seq in:0 out:0); idle; import:admin initiate
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | got payload 0x800(ISAKMP_NEXT_N) needed: 0x0 opt:
0x0
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | ***parse ISAKMP Notification Payload:
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | next payload type: ISAKMP_NEXT_NONE
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | length: 32
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | DOI: ISAKMP_DOI_IPSEC
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | protocol ID: 3
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | SPI size: 16
Aug 26 12:33:54 weiqing-desktop pluto[6933]: | Notify Message Type: NO_PROPOSAL_CHOSEN
Aug 26 12:33:54 weiqing-desktop pluto[6933]: "s1-c1" #3: ignoring informational payload, type
NO_PROPOSAL_CHOSEN msgid=00000000
Cisco
DebugmessageshowthatPhase1iscompleted,butPhase2failedbecauseofpolicynegotiationfailure.
Aug 26 16:03:49 [IKEv1]: Group = 10.20.129.80, IP = 10.20.129.80, PHASE 1 COMPLETED
Aug 26 16:03:49 [IKEv1]: IP = 10.20.129.80, Keep-alive type for this connection: DPD
Aug 26 16:03:49 [IKEv1 DEBUG]: Group = 10.20.129.80, IP = 10.20.129.80, Starting P1 rekey timer:
21600 seconds.
Aug 26 16:03:49 [IKEv1]: IP = 10.20.129.80, IKE_DECODE RECEIVED Message (msgid=b2cdcb13) with
payloads : HDR + HASH (8) + SA (1) + NONCE (10) + KE (4) + ID (5) + ID (5) + NONE
(0) total length : 288
.
.
.
Aug 26 16:03:49 [IKEv1]: Group = 10.20.129.80, IP = 10.20.129.80, Session is being torn down.
Reason: Phase 2 Mismatch
PFS Mismatch
PFSisnegotiatedaspartofPhase2.IfPFSdoesnotmatch,thebehaviorissimilartothefailurecasedescribed
in“Phase2NotMatching”onpage 143.
vShield Edge
000 #4: "s1-c1":500 STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in 8s;
lastdpd=-1s(seq in:0 out:0); idle; import:admin initiate
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | got payload 0x800(ISAKMP_NEXT_N) needed: 0x0 opt:
0x0
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | ***parse ISAKMP Notification Payload:
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | next payload type: ISAKMP_NEXT_NONE
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | length: 32
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | DOI: ISAKMP_DOI_IPSEC
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | protocol ID: 3
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | SPI size: 16
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | Notify Message Type: NO_PROPOSAL_CHOSEN
Aug 26 12:35:52 weiqing-desktop pluto[7312]: "s1-c1" #1: ignoring informational payload, type
NO_PROPOSAL_CHOSEN msgid=00000000
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | info: fa 16 b3 e5 91 a9 b0 02 a3 30 e1 d9 6e
5a 13 d4
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | info: 93 e5 e4 d7
Aug 26 12:35:52 weiqing-desktop pluto[7312]: | processing informational NO_PROPOSAL_CHOSEN (14)
Vue de la page 142
1 2 ... 138 139 140 141 142 143 144 145 146 147 148 ... 161 162

Commentaires sur ces manuels

Pas de commentaire