
Tech Tip
Contivity Secure IP Services Gateway
Configuring Branch Office Tunnel between a Contivity and a BayRS
router
Notification received: Source 10.1.1.2, Dest 10.1.1.1,
Message ID 0x0, SPI length: 16, SPI: 0,
Initial Contact
# 6: 09/13/2004 15:59:17.907 INFO SLOT 1 IKE Code: 21
IKE SA from 10.1.1.1 to 10.1.1.2 is up.
Cipher: DES, Hash: SHA1, Life Type: Minutes, Life Time: 480
# 7: 09/13/2004 15:59:18.021 INFO SLOT 1 IKE Code: 27
Establishing IPsec SA from 10.1.1.1 to 10.1.1.2
using responder role, without perfect forward secrecy. Quick Mode ID
0x3f4a938e.
# 8: 09/13/2004 15:59:18.170 INFO SLOT 1 IKE Code: 28
Quick Mode exchange, ID 0x3f4a938e, from 10.1.1.1 to 10.1.1.2 is up.
Sending negotiated SA information for policy 1 to IPsec.
Reviewing the Contivity event log
The log of the Contivity can be viewed from the GUI through Status Æ Event Log.
Below is a log of a successful tunnel establishment when the Contivity initiates the tunnel:
09/16/2004 14:48:48 0 Branch Office [01] IPSEC branch office connection
initiated to rem[2.1.1.0-255.255.255.0]@[10.1.1.1] loc[3.1.1.0-
255.255.255.0]
09/16/2004 14:48:48 0 Security [11] Session: IPSEC[10.1.1.1] attempting
login
09/16/2004 14:48:48 0 Security [01] Session: IPSEC[10.1.1.1] has no
active sessions
09/16/2004 14:48:48 0 Security [01] Session: IPSEC[10.1.1.1] To ARN has
no active accounts
09/16/2004 14:48:49 0 Security [01] Session: IPSEC[10.1.1.1]:13 SHARED-
SECRET authenticate attempt...
09/16/2004 14:48:49 0 Security [01] Session: IPSEC[10.1.1.1]:13
attempting authentication using LOCAL
09/16/2004 14:48:49 0 Security [11] Session: IPSEC[10.1.1.1]:13
authenticated using LOCAL
09/16/2004 14:48:49 0 Security [11] Session: IPSEC[10.1.1.1]:13 bound to
group /Base/To ARN
09/16/2004 14:48:49 0 Security [01] Session: IPSEC[10.1.1.1]:13 Building
group filter permit all
09/16/2004 14:48:49 0 Security [01] Session: IPSEC[10.1.1.1]:13 Applying
group filter permit all
09/16/2004 14:48:49 0 Security [11] Session: IPSEC[10.1.1.1]:13
authorized
09/16/2004 14:48:49 0 Security [11] Session: network IPSEC[2.1.1.0-
255.255.255.0] attempting login
09/16/2004 14:48:49 0 Security [11] Session: network IPSEC[2.1.1.0-
255.255.255.0] logged in from gateway [10.1.1.1]
09/16/2004 14:48:49 0 ISAKMP [02] ISAKMP SA established with 10.1.1.1
09/16/2004 14:48:49 0 Security [12] Session: IPSEC[10.1.1.1]:13 physical
addresses: remote 10.1.1.1 local 10.1.1.2
TT040916 1.00 September 2004 Page: 15 of 29
Comentarios a estos manuales