
170 C
HAPTER
12: T
ROUBLESHOOTING
G
UIDE
Machines on the
WAN Are Not
Reachable
Make sure the Intranet settings in the Advanced section are correct.
Troubleshooting
the Firewall VPN
Client
If the Firewall client is unable to negotiate with the Firewall, the Firewall
VPN Client Viewer will display detailed error messages. To access the Log
Viewer, select and right click on the icon in the Windows Task Bar and
then select Log Viewer.
To view Log messages, try to initiate a VPN session, either by attempting
to log into the remote Firewall Web interface, or by pinging a machine on
the remote network.
The Log Viewer will display any VPN negotiation errors, such as invalid
SPIs or invalid keys.
Error Message Explanations
■
“New Connection - Initiating IKE Phase 1 (IP
ADDR=10.0.030)
New Connection - SENDING...ISAKMP OAK AG
(SA,KE,NON,ID,VID)
New connection - message not received! Retransmitting!”
This means the VPN client cannot contact the Firewall either because
the VPN client is misconfigured, or the Internet Service Provider for
either the Firewall or the VPN client does not pass IPSec packets.
■
IreIKE:Unable to acquire CAPI provider handle
This indicates that the Firewall VPN client did not install properly.
Completely uninstall the VPN client, restart your computer, and then
reinstall the VPN client to ensure the client software functions
correctly. Confirm that any other IPSec VPN clients have been removed
before reinstalling the Firewall VPN client.
The IKE Negotiation
on the VPN Client
The IKE Negotiation on the VPN Client requires a certain amount of
processor time, before the tunnel opens. This usually takes a few seconds
to complete and some packets may be lost during the process.
There is no negotiation time when using Manual Keys
DUA1611-0AAA02.book Page 170 Thursday, August 2, 2001 4:01 PM
Comentários a estes Manuais