Cisco Systems VPN 3000 Switch User Manual


 
15 Monitoring
15-58
VPN 3000 Concentrator Series User Guide
Phase-2 SA Delete Requests Sent
The cumulative total of requests to delete IPSec Phase-2 Security Associations sent by all currently and
previously active IKE tunnels.
Initiated Tunnels
The cumulative total of IKE tunnels that this VPN Concentrator initiated. The VPN Concentrator
initiates tunnels only for LAN-to-LAN connections.
Failed Initiated Tunnels
The cumulative total of IKE tunnels that this VPN Concentrator initiated and that failed to activate.
Failed Remote Tunnels
The cumulative total of IKE tunnels that remote peers initiated and that failed to activate.
Authentication Failures
The cumulative total of authentication attempts that failed, by all currently and previously active IKE
tunnels. Authentication failures indicate problems with preshared keys, digital certificates, or user-level
authentication.
Decryption Failures
The cumulative total of decryptions that failed, by all currently and previously active IKE tunnels. This
number should be at or near zero; if not, check for misconfiguration or SEP module problems.
Hash Validation Failures
The cumulative total of hash validations that failed, by all currently and previously active IKE tunnels.
Hash validation failures usually indicate misconfiguration or mismatched preshared keys or digital
certificates.
System Capability Failures
The cumulative total of system capacity failures that occurred during processing of all currently and
previously active IKE tunnels. These failures indicate that the system has run out of memory, or that the
tunnel count exceeds the system maximum.
No-SA Failures
The cumulative total of nonexistent-Security Association failures that occurred during processing of all
currently and previously active IKE tunnels. These failures occur when the system receives a packet for
which it has no Security Association, and may indicate synchronization problems.