ZyXEL Communications ISG50 Network Router User Manual


 
Appendix A Log Descriptions
ISG50 User’s Guide
799
Tunnel [%s:%s]
Sending IKE request
The variables represent the phase 1 name and tunnel name. The
device sent an IKE request.
Tunnel [%s:0x%x] is
disconnected
The variables represent the tunnel name and the SPI of a tunnel that
was disconnected.
Tunnel [%s] rekeyed
successfully
%s is the tunnel name. The tunnel was rekeyed successfully.
Table 321 IPSec Logs
LOG MESSAGE DESCRIPTION
Corrupt packet,
Inbound transform
operation fail
The device received corrupt IPsec packets and could not process
them.
Encapsulated packet
too big with length
An outgoing packet needed to be transformed but was longer than
65535.
Get inbound transform
fail
When performing inbound processing for incoming IPSEC packets and
ICMPs related to them, the engine cannot obtain the transform
context.
Get outbound transform
fail
When outgoing packet need to be transformed, the engine cannot
obtain the transform context.
Inbound transform
operation fail
After encryption or hardware accelerated processing, the hardware
accelerator dropped a packet (resource shortage, corrupt packet,
invalid MAC, and so on).
Outbound transform
operation fail
After encryption or hardware accelerated processing, the hardware
accelerator dropped a packet (e.g., resource overflow, corrupt
packet, and so on).
Packet too big with
Fragment Off
An outgoing packet needed to be transformed, but the fragment flag
was off and the packet was too big.
SPI:0x%x SEQ:0x%x
Execute transform step
fail, ret=%d
The variables represent the SPI, sequence number and the error
number. When trying to perform transforming, the engine returned
an error.
SPI:0x%x SEQ:0x%x No
rule found, Dropping
packet
The variables represent the SPI and the sequence number. The
packet did not match the tunnel policy and was dropped.
SPI:0x%x SEQ:0x%x
Packet Anti-Replay
detected
The variables represent the SPI and the sequence number. The device
received a packet again (that it had already received).
VPN connection %s was
disabled.
%s is the VPN connection name. An administrator disabled the VPN
connection.
VPN connection %s was
enabled.
%s is the VPN connection name. An administrator enabled the VPN
connection.
Due to active
connection allowed
exceeded, %s was
deleted.
%s is the VPN connection name. The number of active connections
exceeded the maximum allowed.
Table 320 IKE Logs (continued)
LOG MESSAGE DESCRIPTION