D-Link NetDefend DFL-210 User Manual page 359

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

9.4.5. Troubleshooting with ikesnoop
Authentication algorithm: HMAC (Hash)
Group description: PFS and PFS group
SA life type: Seconds or Kilobytes
SA life duration: Number seconds or kilobytes
Encapsulation mode: Could be transport, tunnel or UDP tunnel (NAT-T)
ID: ipv4(any:0,[0..3]=10.4.2.6)
Here the first ID is the local network of the tunnel from the client's point of view and the second ID
is the remote network. If it contains any netmask it is usually SA per net and otherwise it is SA per
host.
Step 8. Client Sends a List of Supported Algorithms
The server now responds with a matching IPsec proposal from the list sent by the client. As in step 2
above, if no match can be found by the server then a "No proposal chosen" message will be seen,
tunnel setup will fail and the ikesnoop command output will stop here.
IkeSnoop: Sending IKE packet to 192.168.0.10:500 Exchange type :
Quick mode ISAKMP Version : 1.0
Flags
Cookies
Message ID
Packet length
# payloads
Payloads:
HASH (Hash)
Payload data length : 16 bytes
SA (Security Association)
Payload data length : 56 bytes
DOI : 1 (IPsec DOI)
Proposal 1/1
Protocol 1/1
NONCE (Nonce)
Payload data length : 16 bytes
ID (Identification)
Payload data length : 8 bytes
ID : ipv4(any:0,[0..3]=10.4.2.6)
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=10.4.0.0/16)
Step 9. Client Confirms Tunnel Setup
This last message is a message from the client saying that the tunnel is up and running. All
client/server exchanges have been successful.
IkeSnoop: Received IKE packet from 192.168.0.10:500 Exchange type :
Quick mode ISAKMP Version : 1.0
: E (encryption)
: 0x6098238b67d97ea6 -> 0x5e347cb76e95a
: 0xaa71428f
: 156 bytes
: 5
Protocol ID
SPI Size
SPI Value
Transform 1/1
Transform ID
Key length
Authentication algorithm : HMAC-MD5
SA life type
SA life duration
SA life type
SA life duration
Encapsulation mode
: ESP
: 4
: 0xafba2d15
: Rijndael (aes)
: 128
: Seconds
: 21600
: Kilobytes
: 50000
: Tunnel
359
Chapter 9. VPN

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents