
Contivity VPN Switch Interoperability
308630-15.1 Rev 00
D-7
Symptoms You May See
If traffic does not appear to traverse the IPsec tunnel, first check for configuration
mismatches such as the following:
• PFS is enabled on Contivity but not enabled on BayRS for every policy with a
proposal that has the Contivity switch as the destination gateway.
Sample Contivity event log message:
09/02/1999 23:15:53 0 ISAKMP [03] PFS required but not provided
by 144.1.1.152
• Encryption or network addressing does not have matching values with the
remote IPsec gateway configuration.
Sample BayRS event log message:
# 23: 09/02/1999 22:33:27.832 INFO SLOT 1 IKE Code: 130
No Proposal Chosen: Source 10.1.0.1, Dest 144.1.1.152
Message ID 0x0, SPI length: 4, SPI: 1165167
Sample Contivity event log message:
09/02/1999 22:28:38 0 ISAKMP [13] Error notification (No
proposal chosen) received from 144.1.1.152
09/02/1999 22:28:38 0 Security [12] Session: IPSEC[-]:2083
logged out
• BayRS source and destination address ranges do not match the Contivity
branch office remote and local network address ranges derived from the
network and mask specified. If you see the following events repeated in the
Contivity event log, this condition may be present:
09/02/1999 22:49:53 0 ISAKMP [13] Invalid key information in
message from 142.1.1.152
09/02/1999 22:49:53 0 ISAKMP [03] Deleting IPsec SAs with
140.1.1.152:
• BayRS response time is sluggish when you use Site Manager or the
Technician Interface to manage the router.
This problem may be the result of misconfiguration, where PFS is enabled
and IPsec continuously and unsuccessfully attempts to establish an IPsec SA.
This problem may also indicate that the traffic load for the router and
encryption algorithm may be more than the router can process. If triple DES is
in use, change it to DES where possible.
Comentarios a estos manuales