System Logs and Error Messages
432
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Table 125. System logs: IPSec VPN tunnel, Dead Peer Detection and
keep-alive (default 30 sec), VPN tunnel torn down
Message 1
Message 2
Message 3
2000 Jan 1 06:01:18 [SRX5308] [VPNKA] Keep alive to peer 192.168.10.2
failed 3 consecutive times and 5 times cumulative_
2000 Jan 1 06:01:19 [SRX5308] [IKE] DPD R-U-THERE sent to
"20.0.0.1[500]"_
2000 Jan 1 06:01:19 [SRX5308] [IKE] DPD R-U-THERE-ACK received from
"20.0.0.1[500]"_
Explanation Message 1: When the remote host connection is removed and when there are
no packets from the remote host, the VPN firewall sends packets to keep the
remote host alive. As the connection itself is removed, keep-alive fails.
Message 2: The VPN firewall sends packets to check whether the peer is dead.
Message 3: The VPN firewall receives an acknowledgment that the peer is
dead. The connection is removed.
Recommended action None
Table 126. System logs: IPSec VPN tunnel, client policy,
disconnection from the client side
Message 2000 Jan 1 02:34:45 [SRX5308] [IKE] Deleting generated policy for 20.0.0.1[0]_
2000 Jan 1 02:34:45 [SRX5308] [IKE] an undead schedule has been deleted:
'pk_recvupdate'._
2000 Jan 1 02:34:45 [SRX5308] [IKE] Purged IPSec-SA with proto_id=ESP and
spi=3000608295(0xb2d9a627)._
2000 Jan 1 02:34:45 [SRX5308] [IKE] Purged IPSec-SA with proto_id=ESP and
spi=248146076(0xeca689c)._
2000 Jan 1 02:34:45 [SRX5308] [IKE] Purged ISAKMP-SA with proto_id=ISAKMP
and spi=da1f2efbf0635943:4eb6fae677b2e4f4._
2000 Jan 1 02:34:46 [SRX5308] [IKE] ISAKMP-SA deleted for
20.0.0.2[500]-20.0.0.1[500] with spi:da1f2efbf0635943:4eb6fae677b2e4f4_
Explanation Phase 2 and phase 1 policies are deleted when the client is disconnected.
Recommended action None