Console Output CLI Console
Console Output CLI Console
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # diag vpn ike log-filter dst-addr4 61.14.7.148
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # ike 2:Japan_ODC:Japan_ODC: IPsec SA connect 9
192.8.202.121->61.14.7.148:0
ike 2:Japan_ODC:Japan_ODC: using existing connection
ike 2:Japan_ODC:Japan_ODC: traffic triggered, serial=1 1:10.115.90.15:2048-
>1:10.122.28.144:0
ike 2:Japan_ODC:Japan_ODC: config found
ike 2:Japan_ODC: request is on the queue
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # ike 2: comes 61.14.7.148:500-
>192.8.202.121:500,ifindex=9,vrf=0....
ike 2: IKEv2 exchange=INFORMATIONAL id=ccd4fdab6a42dd31/34e797fd7453e4bb:00000ae5
len=80
ike 2: in
CCD4FDAB6A42DD3134E797FD7453E4BB2E20250000000AE500000050000000344769112900CB639A6FC
505D577053B63E0FD327BE04F19F993D7E5731B8C3FBD
CC08C10370C680D22CD212FAE8D7A3D1
ike 2:Japan_ODC: HA state master(2)
ike 2:Japan_ODC:1689768: dec
CCD4FDAB6A42DD3134E797FD7453E4BB2E20250000000AE50000002000000004
ike 2:Japan_ODC:1689768: received informational request
ike 2:Japan_ODC:1689768: enc 0F0E0D0C0B0A0908070605040302010F
ike 2:Japan_ODC:1689768: out
CCD4FDAB6A42DD3134E797FD7453E4BB2E20252800000AE50000005000000034496E299643AE0C0C3FC
7E351B6C9DE6BED071A9F508E4
351DFAF492138527DCC276DFB1E35E2647BF7E5E84498DF2A7A
ike 2:Japan_ODC:1689768: sent IKE msg (INFORMATIONAL_RESPONSE): 192.8.202.121:500-
>61.14.7.148:500, len=80, vrf=0, id=ccd4fdab6a42dd31/34e
797fd7453e4bb:00000ae5
ike 2:Japan_ODC:Japan_ODC: IPsec SA connect 9 192.8.202.121->61.14.7.148:0
ike 2:Japan_ODC:Japan_ODC: using existing connection
ike 2:Japan_ODC:Japan_ODC: traffic triggered, serial=1 1:10.115.90.15:2048-
>1:10.122.28.144:0
ike 2:Japan_ODC:Japan_ODC: config found
ike 2:Japan_ODC: request is on the queue
ike 2:Japan_ODC:Japan_ODC: IPsec SA connect 9 192.8.202.121->61.14.7.148:0
ike 2:Japan_ODC:Japan_ODC: using existing connection
ike 2:Japan_ODC:Japan_ODC: traffic triggered, serial=1 1:10.115.90.15:2048-
>1:10.122.28.144:0
ike 2:Japan_ODC:Japan_ODC: config found
ike 2:Japan_ODC: request is on the queue
ike 2: comes 61.14.7.148:500->192.8.202.121:500,ifindex=9,vrf=0....
ike 2: IKEv2 exchange=CREATE_CHILD id=ccd4fdab6a42dd31/34e797fd7453e4bb:00000ae6
len=400
ike 2: in
CCD4FDAB6A42DD3134E797FD7453E4BB2E20240000000AE60000019029000174323B09A2A6F520E252B
8FA644FA0B6D910519AEA57A595C02505661B2D9A46F6
560A167A9177374B8433F870B884647F3205AFC4764EC35655AE11E02336CA2FDA41DC1DADE9C048784
F0CE047A6EFAC6AD98E4716EF678FF63C243D78F1029D6C2FD36340
6D56D70C95D38B5EA6C2988BCB2E88D4F162FBAEE5E4F40343B4056EEAAD5D20E29A80AA58EF902A2F3
21A515738EF39F62BC9AB7D02A8171E44458F3C8674902D9CC2C4D2
37C9721A21C2AC288DBF29338A0A6E202715751880F14622268917E71CEAB37A49ACD2C037956011261
774D30AA19648F9EC16455166B115223E058C0959DFF89CEEFB0077
DC381C578004350104CB5A74DE4121905298D344F07BFCB66D33668E4F7897C9BC762CA8AB34999C885
EF6C634FCD3C2F01B21C0C2A6BB73946F32568194D156EAD44BC8C2
4A3AFFD2E6702C3EB846290B4EB57EBE67FD9C927FD404CCE40E35D8AE4AA90FB7743404511A86648A2
05AD2E0DE70700C0588BFB5499F9FC704FB1C
ike 2:Japan_ODC: HA state master(2)
ike 2:Japan_ODC:1689768: dec
CCD4FDAB6A42DD3134E797FD7453E4BB2E20240000000AE60000016829000004210000080000400A280
000340000003001030404CF495
1AA0300000C0100000C800E0100030000080300000C0300000804000014000000080500000022000024
F2846D91EBD374D6C2A7F64D18779C96A46D067473A31C1435F2839
C42049F9E2C00006800140000953FB418CA58399150089DD792A5A0FD1A489ED11DC38BA222B7D3F9F1
839FD050C1FE3D3CD5B30019644BD0542EC6DB916175CE12D4CC7FD
E0DB9EBF16F002ABC6E026A57259D45D45E44660DB3E5E0E208EE089EE9AC257E273D52AFA635672D00
004002000000070000100000FFFF00000000FFFFFFFF08000028000
0FFFF00000000000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000040020000
00070000100000FFFF00000000FFFFFFFF080000280000FFFF00000
000000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
ike 2:Japan_ODC:1689768: received create-child request
ike 2:Japan_ODC:1689768: responder received CREATE_CHILD exchange
ike 2:Japan_ODC:1689768: processing notify type ESP_TFC_PADDING_NOT_SUPPORTED
ike 2:Japan_ODC:1689768: responder creating new child
ike 2:Japan_ODC:1689768:57544: peer proposal:
ike 2:Japan_ODC:1689768:57544: TSi_0 0:0.0.0.0-255.255.255.255:0
ike 2:Japan_ODC:1689768:57544: TSi_1 0:::-ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff:0
ike 2:Japan_ODC:1689768:57544: TSr_0 0:0.0.0.0-255.255.255.255:0
ike 2:Japan_ODC:1689768:57544: TSr_1 0:::-ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff:0
ike 2:Japan_ODC:1689768:Japan_ODC:57544: comparing selectors
ike 2:Japan_ODC:1689768:Japan_ODC:57544: matched by rfc-rule-3
ike 2:Japan_ODC:1689768:Japan_ODC:57544: phase2 matched by subset
ike 2:Japan_ODC:1689768:Japan_ODC:57544: accepted proposal:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: TSi_0 0:0.0.0.0-255.255.255.255:0
ike 2:Japan_ODC:1689768:Japan_ODC:57544: TSr_0 0:0.0.0.0-255.255.255.255:0
ike 2:Japan_ODC:1689768:Japan_ODC:57544: autokey
ike 2:Japan_ODC:1689768:Japan_ODC:57544: incoming child SA proposal:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: proposal id = 1:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: protocol = ESP:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: encapsulation = TUNNEL
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=ENCR, val=AES_CBC (key_len =
256)
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=INTEGR, val=SHA256
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=DH_GROUP, val=ECP384
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=ESN, val=NO
ike 2:Japan_ODC:1689768:Japan_ODC:57544: my proposal:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: proposal id = 1:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: protocol = ESP:
ike 2:Japan_ODC:1689768:Japan_ODC:57544: encapsulation = TUNNEL
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=ENCR, val=AES_CBC (key_len =
256)
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=INTEGR, val=SHA256
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=DH_GROUP, val=MODP1536
ike 2:Japan_ODC:1689768:Japan_ODC:57544: type=ESN, val=NO
ike 2:Japan_ODC:1689768:Japan_ODC:57544: lifetime=3600
ike 2:Japan_ODC:1689768:Japan_ODC:57544: no proposal chosen
ike Negotiate SA Error: ike ike [1481]
ike 2:Japan_ODC:1689768:Japan_ODC:57544: responder preparing CREATE_CHILD message
ike 2:Japan_ODC:1689768: enc 000000080000000E0706050403020107
ike 2:Japan_ODC:1689768: out
CCD4FDAB6A42DD3134E797FD7453E4BB2E20242800000AE60000005029000034ECC27C78A32EA6D25D8
2800754F2BD668C8CF139D542F
6A2AC4E4CACF460244435291220D6C990DCAEC8A48155F97F0D
ike 2:Japan_ODC:1689768: sent IKE msg (CREATE_CHILD_RESPONSE): 192.8.202.121:500-
>61.14.7.148:500, len=80, vrf=0, id=ccd4fdab6a42dd31/34e7
97fd7453e4bb:00000ae6
ike 2:Japan_ODC:1689768:57544: no proposal chosen
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # ike 2:Japan_ODC:Japan_ODC: IPsec SA connect 9
192.8.202.121->61.14.7.148:0
ike 2:Japan_ODC:Japan_ODC: using existing connection
ike 2:Japan_ODC:Japan_ODC: traffic triggered, serial=1 1:10.115.92.47:2048-
>1:10.115.93.242:0
ike 2:Japan_ODC:Japan_ODC: config found
ike 2:Japan_ODC: request is on the queue
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # di de ike 2:Japan_ODC:Japan_ODC: IPsec SA connect 9
192.8.202.121->61.14.7.148:0
ike 2:Japan_ODC:Japan_ODC: using existing connection
ike 2:Japan_ODC:Japan_ODC: traffic triggered, serial=1 1:10.115.90.15:2048-
>1:10.115.93.243:0
ike 2:Japan_ODC:Japan_ODC: config found
ike 2:Japan_ODC: request is on the queue
di
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) # di de di
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #
FortiGate-2601F (vsys3) #