1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Other Subject - Log Explanation

Log Explanation

  1. Toxic
    No acceptable Oakley Transform, No Proposal chosen.
    No acceptable Proposal in IPsec SA
    Multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used
    IDci, IDcr payloads missing in message but default does not match proposal
    We require PFS but Quick I1 SA specifies no GROUP_DESCRIPTION
    Cannot respond to IPsec SA request because no connection is known for %s
    Received Hash Payload does not match computed value
    %s ID payload %s bad subnet in Quick I1 (%s)
    No suitable connection for peer '%s', please check Phase 1 ID value
    Peer's ID_USER_FQDN contains no @
    Improper "?" identification payload: "?"
    Protocol in Phase 1 ID Payload must be 0 or %d ,Port number must be 0 or 500 but now are %d/%d (Protocol/Port)
    No interface for this connection, VPN IPSec didn't detect any outbound interface
    KE has "?" byte DH public value; "?" required
    Missing KE payload in %s message, Peer may not have PFS
    Ignoring Delete SA payload: not encrypted
    Ignoring Delete SA payload ISAKMP SA not established
    Ignoring Delete SA payload: no SPI
    Ignoring Delete SA payload: invalid size
    Ignoring Delete SA payload: unknown Protocol ID "?"
    Received Delete SA payload: deleting ISAKMP State "?"
    Ignoring Delete SA payload: ISAKMP SA not found (maybe expired)

    No acceptable Oakley Transform, No Proposal chosen.
    Peer Phase 1 SA value (Including Encryption Algorithm, Authentication Method) is not configured correct!

    No acceptable Proposal in IPsec SA
    Peer Phase 2 SA value (Including Encryption Algorithm, Authentication Method) is not configured correct!

    Multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used
    If you set two tunnels with same endpoint but different preshared key, first one will be chosen

    IDci, IDcr payloads missing in message but default does not match proposal
    Peer ID value is not correct

    We require PFS but Quick I1 SA specifies no GROUP_DESCRIPTION
    We have set PFS for this tunnel, but the peer does not enable PFS

    Cannot respond to IPsec SA request because no connection is known for %s
    The phase 2 secure subnet/IP/Range is not match with our configuration

    Received Hash Payload does not match computed value
    Authentication Failure,the peer IP/ID/PSK might be wrong or sniffer try to replay the packet to crack in our system.

    %s ID payload %s bad subnet in Quick I1 (%s)
    The peer secure subnet is not the same with our configuration; please check the secure subnet type (IPv4, Suubnet, Range) or the secure subnet value

    No suitable connection for peer '%s', please check Phase 1 ID value
    The peer ID do not match with our tunnel configuration, please check phase 1 ID value

    Peer's ID_USER_FQDN contains no "@"
    The peer use USER_FQDN (Email) as their ID type but string contain no "@"

    Improper "?" identification payload: "?"
    The peer ID is not same with us

    Protocol in Phase 1 ID Payload must be 0 or %d ,Port number must be 0 or 500 but now are %d/%d (Protocol/Port)
    The peer does not use UDP port 500 as IPSec handshaking protoccol/port!

    No interface for this connection, VPN IPSec didn't detect any outbound interface
    There is no WAN interface available for this connection

    KE has "?" byte DH public value; "?" required
    Peer DH group value is not match with us.

    Missing KE payload in %s message, Peer may not have PFS
    Peer is not setting PFS, but we set PFS enable for this tunnel.

    Ignoring Delete SA payload: not encrypted
    This incoming delete SA packet should have been encrypted, peer gateway internal failure.

    Ignoring Delete SA payload ISAKMP SA not established
    Incoming delete SA packet is discarded, because the phase 1 SA still not established.

    Ignoring Delete SA payload: no SPI
    Incoming delete SA packet is discarded, because there is not matching tunnel for this packet.

    Ignoring Delete SA payload: invalid size
    Incoming delete SA packet is discarded, because the packet size is not correct.

    Ignoring Delete SA payload: unknown Protocol ID "?"
    Incoming delete SA packet is discarded, because the protocol ID is not correct.

    Received Delete SA payload: deleting ISAKMP State "?"
    We accept peer Delete SA payload".

    Ignoring Delete SA payload: ISAKMP SA not found (maybe expired)
    We reject peer "Delete SA payload" , because SA not found.