ZyXEL Communications ZyWALL 1000 Network Router User Manual


 
Appendix B Log Descriptions
ZyWALL USG 1000 User’s Guide
679
Tunnel [%s:%s]
Sending IKE request
The variables represent the phase 1 name and tunnel name. The
device sent an IKE request.
Tunnel [%s:0x%x] is
disconnected
The variables represent the tunnel name and the SPI of a tunnel that
was disconnected.
Tunnel [%s] rekeyed
successfully
%s is the tunnel name. The tunnel was rekeyed successfully.
Table 243 IPSec Logs
LOG MESSAGE DESCRIPTION
Corrupt packet,
Inbound transform
operation fail
The device received corrupt IPsec packets and could not process
them.
Encapsulated packet
too big with length
An outgoing packet needed to be transformed but was longer than
65535.
Get inbound transform
fail
When performing inbound processing for incoming IPSEC packets and
ICMPs related to them, the engine cannot obtain the transform
context.
Get outbound transform
fail
When outgoing packet need to be transformed, the engine cannot
obtain the transform context.
Inbound transform
operation fail
After encryption or hardware accelerated processing, HWAccel
dropped packet (resource shortage, corrupt packet, invalid MAC, and
so on).
Outbound transform
operation fail
After encryption or hardware accelerated processing, Hwaccel
dropped packet (e.g., resource overflow, corrupt packet, and so on).
Packet too big with
Fragment Off
An outgoing packet needed to be transformed, but the fragment flag
was off and the packet was too big.
SPI:0x%x SEQ:0x%x
Execute transform step
fail, ret=%d
The variables represent the SPI, sequence number and the error
number. When trying to perform transforming, the engine returned an
error.
SPI:0x%x SEQ:0x%x No
rule found, Dropping
packet
The variables represent the SPI and the sequence number. The
packet did not match the tunnel policy and was dropped.
SPI:0x%x SEQ:0x%x
Packet Anti-Replay
detected
The variables represent the SPI and the sequence number. The device
received a packet again (that it had already received).
VPN connection %s was
disabled.
%s is the VPN connection name. An administrator disabled the VPN
connection.
VPN connection %s was
enabled.
%s is the VPN connection name. An administrator enabled the VPN
connection.
Table 242 IKE Logs (continued)
LOG MESSAGE DESCRIPTION