
Tech Tip
Contivity Secure IP Services Gateway
Configuring Branch Office Tunnel between a Contivity and a BayRS
router
Reviewing the BayRS Router event log
The log of the tunnel establishment on the ARN can be viewed from the TI (command line of
console or telnet) by using “log –ffwdit –eIKE –eIPSEC”. This is the log of a successful
tunnel establishment when ARN initiates the connection:
# 1: 09/13/2004 15:51:21.257 TRACE SLOT 1 IKE Code: 35
IKE SA not found for IKE peer 10.1.1.2, interface 10.1.1.1,
beginning negotiation for new IKE SA
# 2: 09/13/2004 15:51:21.258 INFO SLOT 1 IKE Code: 20
Establishing IKE SA from 10.1.1.1 to 10.1.1.2,
using initiator role.
# 3: 09/13/2004 15:51:23.632 INFO SLOT 1 IKE Code: 115
Notification received: Source 10.1.1.2, Dest 10.1.1.1,
Message ID 0x0, SPI length: 16, SPI: 0,
Initial Contact
# 4: 09/13/2004 15:51:23.642 INFO SLOT 1 IKE Code: 21
IKE SA from 10.1.1.1 to 10.1.1.2 is up.
Cipher: 3DES, Hash: SHA1, Life Type: Minutes, Life Time: 480
# 5: 09/13/2004 15:51:23.643 INFO SLOT 1 IKE Code: 27
Establishing IPsec SA from 10.1.1.1 to 10.1.1.2 for policy 1
using initiator role, without perfect forward secrecy. Quick Mode ID
0x820be868.
# 6: 09/13/2004 15:51:23.818 INFO SLOT 1 IKE Code: 28
Quick Mode exchange, ID 0x820be868, from 10.1.1.1 to 10.1.1.2 is up.
Sending negotiated SA information for policy 1 to IPsec.
Below is the log of a successful tunnel establishment when the ARN responds to the connection:
# 1: 09/13/2004 15:59:16.715 INFO SLOT 1 IKE Code: 20
Establishing IKE SA from 10.1.1.1 to 10.1.1.2,
using responder role.
# 2: 09/13/2004 15:59:16.733 INFO SLOT 1 IKE Code: 117
Invalid Payload Type: Source 10.1.1.2, Dest 10.1.1.1,
Message ID 0x0, SPI length: 0, SPI: 0
# 3: 09/13/2004 15:59:16.735 INFO SLOT 1 IKE Code: 22
IKE SA not established from 10.1.1.1 to 10.1.1.2
# 4: 09/13/2004 15:59:16.739 INFO SLOT 1 IKE Code: 20
Establishing IKE SA from 10.1.1.1 to 10.1.1.2,
using responder role.
# 5: 09/13/2004 15:59:17.873 INFO SLOT 1 IKE Code: 115
TT040916 1.00 September 2004 Page: 14 of 29
Comentarios a estos manuales