Manuel d'utilisation / d'entretien du produit NN46110-602 du fabricant Nortel Networks
Aller à la page of 230
Version 7.00 Part No. NN46110-602 315900-E Rev 01 February 2007 Document status: Standard 600 Technology Park Drive Billerica, MA 01821-4130 Nor tel VPN Router T r oub l eshooting.
2 NN46110-602 Copyright © 2007 Nortel Ne tworks. All rights reserved. The information in this document is subj ect to change without notice. The statements, config urations, technical d a ta, and recommendations in this docume nt are believ ed to be accura te and reliable, but are presen ted without e xpress or implied warranty .
3 Nortel VPN Router Tr oubleshoot ing Portions of the code in this softw are product may be Copyright © 1988, Regents of the Uni ver sity of California.
4 NN46110-602 3. Limitation of Remedies. IN NO EVENT SHALL NOR TEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE LIABLE FOR ANY OF THE FOLLO WING: a) DAMA GES B A SED ON ANY THIRD P AR TY CLAIM; b) LOS S OF .
5 Nor tel VPN Router T roubleshootin g Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Bef ore you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
6 Contents NN46110-602 Configuring SNMP traps to send notification when an IP address pool reaches the configured threshold . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Chapter 2 Status and logging . .
Contents 7 Nor tel VPN Router T roubleshootin g Using SFTP to transfer back u p files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Stopping the transf e r of backup files using S FTP . . . . . . . . . . . . . . . . . . . . . . 59 Disabling new logins .
8 Contents NN46110-602 System problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96 Solving routing problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Contents 9 Nor tel VPN Router T roubleshootin g Viewing a pack et c apture outpu t file on a PC . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 Installing Ethereal software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
10 Contents NN46110-602 Appendix B Using serial PPP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165 Establishing a serial PPP connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Contents 11 Nor tel VPN Router T roubleshootin g IPX client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Windows 95 and Windows 98 . . . . . . . . . . . . . . . . . . . . . . . . . .
12 Contents NN46110-602.
13 Nor tel VPN Router T roubleshootin g Figures Figure 1 Admin > SNMP T raps window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Figure 2 Event logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14 Figures NN46110-602.
15 Nor tel VPN Router T roubleshootin g Ta b l e s T able 1 Field IDs for data collection r ecords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 T able 2 T roubleshooti ng tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
16 Tables NN46110-602.
17 Nortel VPN Rout er Troubleshooting Preface This guide provides information about how to manage and trou bleshoot the Nortel VPN Router . Bef ore you begin This guide is for network managers wh o monitor and mainta in the Nortel VPN Router .
18 Prefac e NN46110-602 braces ({}) Indicate required elements in syntax descripti ons where there is more than one optio n. Y ou must choose only one of the options.
Preface 19 Nortel VPN Router Tr oubleshoot ing Acr onyms This guide uses the follo wing acronyms: vertical line ( | ) Separates choices for command keywords and arguments. En ter only one of the choices. Do not type the vertical line when entering the command.
20 Prefac e NN46110-602 L2TP Layer 2 T unneling Proto col LAN local area network LD AP Lightweight Directory Access Protocol N A T Network Address T ranslation OSI Open Systems Interconnection OSPF Op.
Preface 21 Nortel VPN Router Tr oubleshoot ing Related publications For more information about the Nort el VPN Router, see the follo wing publications: • Release notes prov ide the latest inform ation, including brief descriptions of the ne w features, problems fix ed in this release, and kno wn problems and workarounds.
22 Prefac e NN46110-602 Har d -copy tec hnical manuals Y ou can print selected technical manuals and release notes free, directly from the Internet. Go to www .nortelnetworks.com/documentation , find the product for which you need do cumentation, then lo cate the specif ic category and model or version for your hardw are or software product.
Preface 23 Nortel VPN Router Tr oubleshoot ing Getting help fr om the Nor tel W eb site The best way to get techni cal support for Nortel products is from the Nortel T echnical Support W eb site: www .nortel.com/support This site provides quick access to softw are, documentation, bulletins, and tools to address issues with Nortel prod ucts.
24 Prefac e NN46110-602 Getting help thr o ugh a Nor t el distributor or reseller If you purchased a service contract for you r Nortel product from a distrib utor or authorized reseller , contact the technica l support staff for that distrib utor or reseller .
25 Nortel VPN Rout er Troubleshooting Ne w in this release The follo wing section details what is new in Nortel VPN Router T r oubleshooting for Release 7.
26 New in this release NN46110-602 A utomatic backups Y ou can now back up a f ile or a directory , as well as trigger a backup, when a f ile changes. Previously , yo u could only back up system, configuration, and log files. Y ou can use either the graphical user interface (GUI) or the command line interface (CLI) to conf igure automated backup.
27 Nortel VPN Rout er Troubleshooting Chapter 1 VPN Router administration This chapter introduces administrator se ttings, tools, system conf iguration, and file management. It also include s information about SNMP traps. Administrator settings The VPN Router supports multiple administ rators.
28 Chapter 1 VPN Router adm inistration NN46110-602 Y ou use the Administrator Settin gs window to do the follo wing : • change the primary admi nistrator user ID and passw ord • control the Admin.
Chapter 1 VPN Router administration 29 Nortel VPN Router Tr oubleshoot ing Dynamic pass w ord T wo types of administrative users exist on the VPN Router: • one super -user (Administrator) • as many administrati ve users as needed There is dynamic password support for administrati ve users only .
30 Chapter 1 VPN Router adm inistration NN46110-602 The T raceroute tool measure s a network ro und-trip delay . Messages are sent per hop and the wait occurs between each message. If the address is unreachable, it uses the following formula to determin e how long it takes for the Traceroute to time out.
Chapter 1 VPN Router administration 31 Nortel VPN Router Tr oubleshoot ing Simple Netw ork Management Protocol (SNMP) Use the Admin > SNMP window to do t h e follo wing: • designate the remote SN.
32 Chapter 1 VPN Router adm inistration NN46110-602 The traps displayed on the g roup window s—in particular the Hardware T rap Configuration and the Service T rap Conf iguration windows—reflect the hardw are and software av ailable on your VPN Router.
Chapter 1 VPN Router administration 33 Nortel VPN Router Tr oubleshoot ing Figure 1 Admin > SNMP T raps windo w 2 Enter a host name or IP address in the Host Name or IP Addr ess text box. 3 Enter a name in the Community Name te xt box. 4 Click Enable .
34 Chapter 1 VPN Router adm inistration NN46110-602 T o configure the amount: CES(config)# ip local pool exhausted- amount <amount>.
35 Nortel VPN Rout er Troubleshooting Chapter 2 Status and logging The Status windo ws show which users are logged on, their traff ic demands, and a summary of the VPN Router’ s hardw are configuration, including a v ailable memory and disk space.
36 Chapter 2 Status and logging NN46110-602 Most e vents are sent to the e vent log f irs t. Significant e vents from the e vent log are sent to the system log.
Chapter 2 Sta tus and logging 37 Nortel VPN Router Tr oubleshoot ing If you ha ve multiple VPN Routers throughou t the world, use the Greenwich Mean T ime (GMT) standard to synchronize the v arious log files so that the timestamps are directly comparable.
38 Chapter 2 Status and logging NN46110-602 Accounting The accounting log provides information ab out user sessi ons. This log provides last and first names, user ID, tunnel ty pe, session start and end dates, and the number of packets and b ytes transferred.
Chapter 2 Sta tus and logging 39 Nortel VPN Router Tr oubleshoot ing The data collection system stores records in te xt-bas ed files stored in the system/ dclog subdirectory . The system stores the most recent 60 days of data. The system stores daily files, summary files, and summary history f iles.
40 Chapter 2 Status and logging NN46110-602 • Summary file that al ways has exactly f i ve records containing summary data in a file called summary .
Chapter 2 Sta tus and logging 41 Nortel VPN Router Tr oubleshoot ing Logs The VPN Router has se veral logs that pr ov ide dif ferent lev els of information. The logs are stored in text files and indicate what happened, wh en the e vent occu rred, and the IP address and user ID of the person causing the e vent.
42 Chapter 2 Status and logging NN46110-602 As the e vent log adds inform ation, the oldest entries are ov erwritten. The ev ent log retains the latest 2000 entries and dis cards old entries when it is refreshed. T o configure e vent logging: 1 Select Status > Event Log .
Chapter 2 Sta tus and logging 43 Nortel VPN Router Tr oubleshoot ing Figure 3 Capture and dis play f ilters 5 Y ou configure the capture f ilter and di splay filter using Entity-Subentity or Se verity . T o configure the capture f ilter or display filter: a Click Conf igure Captur e Entity or Configur e Display Entity .
44 Chapter 2 Status and logging NN46110-602 Figure 4 Configure Display Entity b Select an Entity from the list. c Select a Subentity from the list. d Click Add to add the selected entity-s ubentity pair to the filter . e Click Accept to complete your changes to the filter .
Chapter 2 Sta tus and logging 45 Nortel VPN Router Tr oubleshoot ing System log The system log contains all system ev ents that are considered significant enough to be written to disk, including those disp layed in the conf iguration and security logs.
46 Chapter 2 Status and logging NN46110-602 • communications with servers •L D A P • Remote Authentication Dial-In User Service (RADIUS) Configuration log The Conf iguration log records all configuration changes.
47 Nortel VPN Rout er Troubleshooting Chapter 3 Administrative tasks This chapter describes administrativ e task s that help you operate the VPN Router. These tasks provide details on scheduling backups, up grading the software image, saving conf iguration files, performing f ile maintenance, creating recov ery diskettes, and system shutdo wn.
48 Chapter 3 Administrative tasks NN46110-602 Reco ver y In the unlikely e vent that there is a hard disk crash, use the Reco very windo w to configure a reco very diskette to restore the software image and f ile system to the hard driv e of the VPN Router.
Chapter 3 Administrative tasks 49 Nortel VPN Router Tr oubleshoot ing This supplies a minimal conf iguration u tility so that you can vie w the VPN Router from a W eb browser . 3 In the W eb bro wser , enter the management IP address of the VPN Router.
50 Chapter 3 Administrative tasks NN46110-602 • Select Restor e Factory Conf iguration , then click Restore to return the VPN Router to its original factory def ault co nfiguration. This erases data co ntained in flash memory and also in the configuration f ile.
Chapter 3 Administrative tasks 51 Nortel VPN Router Tr oubleshoot ing Y ou can use a new f actory default softwa re image and f ile system to restore the VPN Router’ s hard disk. Specify the name or address and path of the network f ile server ont o which the softwa re from the Nortel CD is installed.
52 Chapter 3 Administrative tasks NN46110-602 12 Click Synchr onize to immediately syn c hronize the primary and second ary disks. Thereafter , the disks auto matically synchronize e very hour . 13 From the list, select the driv e on which you want to upgrade the syste m boot software.
Chapter 3 Administrative tasks 53 Nortel VPN Router Tr oubleshoot ing Y ou must create a directory on the File T ransfer Protocol (FTP) or Secu re File T ransfer Protocol (SFTP) server before running automatic backup.
54 Chapter 3 Administrative tasks NN46110-602 T o enable automatic backup when a file or a directory changes: 1 Select Admin > A uto Backup . The Automatic Backup window appears. (Figure 6) Figure 6 Automatic back up window 2 Click Enabled to enable the associated host backup f ile server .
Chapter 3 Administrative tasks 55 Nortel VPN Router Tr oubleshoot ing 7 T o back up at certain interv als of time, click Interval and in the Interval text box specify in hours the time peri od af ter which the system automatically backs up changed files.
56 Chapter 3 Administrative tasks NN46110-602 Figure 7 Specific A utomatic Backup windo w 14 T o see the list of f iles for a directory , highlight the name of a directory and click Display . The fil es for that directory appear in the Files list. 15 T o select the file th at you want to back up, hig h light the name of the f ile and click Select .
Chapter 3 Administrative tasks 57 Nortel VPN Router Tr oubleshoot ing 22 Click Backup to run the backup to each enabled server now . This action also synchronizes the hard disk dri ves when there is more than one hard driv e in a device. Otherwise, the hard disks synchronize automatically every 60 minutes.
58 Chapter 3 Administrative tasks NN46110-602 Backing up specific f iles and directories T o back up specific f iles and directorie s, with the option to delete them after backup, enter: exception bac.
Chapter 3 Administrative tasks 59 Nortel VPN Router Tr oubleshoot ing Stopping the backup of c hanges to specific files or directories T o stop backing up the changes for specif ic files or directorie.
60 Chapter 3 Administrative tasks NN46110-602 Disabling ne w logins Y ou can prev ent clients from connec ting to the VPN Router without af fecting the users currently connected b y using this feature to disable ne w logins. When new logins is disabled, no ne w IP sec connections are established.
Chapter 3 Administrative tasks 61 Nortel VPN Router Tr oubleshoot ing • Nortel W eb site • your o wn FTP site if you previously do wnloaded the software from the Nortel FTP site • Nortel software CD If an FTP serv er does not use standard FTP port numbers, you canno t use it to do wnload FTP servers for Nortel software .
62 Chapter 3 Administrative tasks NN46110-602 Before you upgrade your software, use o n e of the follo wing methods to make sure there is enough av ailable disk space: • From the GUI, select Status > Statistics > File System . The last line lists the free space on the disk.
Chapter 3 Administrative tasks 63 Nortel VPN Router Tr oubleshoot ing 5 Ty p e 5 ( Create A User Control Tunnel (IPsec) Profile ). 6 Enter the user ID that you plan to use to log in remotely to the VPN Router . 7 Enter the password that you plan to use.
64 Chapter 3 Administrative tasks NN46110-602 b Click Backup to start the backup immediately . This sav es your entire hard driv e, incl uding the LD AP and configuration f iles. Retrieving the ne w software For V ersion 4.80 and later , the VPN Ro uter release image is a vailable in a compressed .
Chapter 3 Administrative tasks 65 Nortel VPN Router Tr oubleshoot ing Figure 9 sho ws an example upgrade to V04_80.114 from server 192.32.250.64. The file V04_80.114.tar .gz must be located at the root of the FTP directory . Figure 9 FTP menu e xample When you FTP to the FTP serv er from another PC, you see the location of the file.
66 Chapter 3 Administrative tasks NN46110-602 • User ID: type the login ID required to gain access to the FTP server where the ne w VPN Router software is located. • Passw ord and Confirm Passw ord: type the password (twice) that corresponds to the user ID you just entered.
Chapter 3 Administrative tasks 67 Nortel VPN Router Tr oubleshoot ing — Response Timeout f or RADI US A ccounting Server — External RADIUS Accounting Server b Click OK . Applying the software After you start the apply process, do not make any qu eries on the VPN Router.
68 Chapter 3 Administrative tasks NN46110-602 6 Select a system shutdo wn type of None and cl ick OK . Y ou have successfully upgraded your switch..
69 Nortel VPN Rout er Troubleshooting Chapter 4 T r oubleshooting This chapter introduces the concepts and practices of advanced network configuration and troubleshooting fo r the Nortel VPN Router.
70 Chapter 4 Troubl eshooting NN46110-602 T roubleshooting remote access problems typica lly starts at the client end when the remote user cannot establish a connection, loses a connection, or has diff iculty bro wsing the network or printing.
Chapter 4 Tr oubleshooting 71 Nortel VPN Router Tr oubleshoot ing Microsoft Point-to-Point T unneling Pr otocol (PPTP) Dial-Up Network ing Monitor provides network statistics on device, connection, and network protocols that help monitor traf fic flow and a ssess PPTP connection performance.
72 Chapter 4 Troubl eshooting NN46110-602 Solving connectivity pr oblems This section lists man y of the common co nnecti v ity problems that occur and their recommended solutio ns.
Chapter 4 Tr oubleshooting 73 Nortel VPN Router Tr oubleshoot ing 1 Confirm that the modem is attached and working properly by running a terminal emulation program at thei r remote workstation, such as, Hyperterminal*, and issuing the A T command. If the response is AT O K , the modem is operating correctly .
74 Chapter 4 Troubl eshooting NN46110-602 Remote host not responding Cause: This indicates that the VPN Router ne ver respon ded to the IPsec connection attempt or that User Datagram Protocol (UDP) port 500 is blocked.
Chapter 4 Tr oubleshooting 75 Nortel VPN Router Tr oubleshoot ing Action: V erify that the user name you entere d is correct and retype the password before trying the con nection again.
76 Chapter 4 Troubl eshooting NN46110-602 Action: Click Connect to re-establish the extranet connection. If this works, the connection was probably lost due to th e Idle T imeout conf igured on the VPN Router.
Chapter 4 Tr oubleshooting 77 Nortel VPN Router Tr oubleshoot ing Action: V alidate that the VPN Client is configured with a DNS entry . For W indo ws NT 4.0, open a command prompt and enter ipconfig/all . V erify that a DNS server entry is listed. For W indows 95, from the Start menu on the task bar , select Run and enter winipcfg .
78 Chapter 4 Troubl eshooting NN46110-602 Cannot access W eb servers on the Internet afte r establishing a VPN Client connection Cause : For both PPTP and IPsec, this condition occurs as a result of all network traf fic passing through the corporate network.
Chapter 4 Tr oubleshooting 79 Nortel VPN Router Tr oubleshoot ing Alternati vely , on NT 4.0, W indows 98, and W indows 95, compl e te the follo wing steps to change your workstation to be a member of a workgroup instead of a domain: 1 From the Start menu, select Settings > Contr ol Panel .
80 Chapter 4 Troubl eshooting NN46110-602 • Start from the top do wn to go in the opposite direction, looking at PPP first and working down to the ph ysical connection.
Chapter 4 Tr oubleshooting 81 Nortel VPN Router Tr oubleshoot ing Check the HDLC framing Assuming that the T1/V .35 interface is op erating correctly , use the follo wing steps to determine whether th.
82 Chapter 4 Troubl eshooting NN46110-602 4 If the PPP layer still does not come up, enable the interface debugger to generate large amounts of packet tr aces in the e vent log. Report this information to Nortel Customer Support for further diagnosis.
Chapter 4 Tr oubleshooting 83 Nortel VPN Router Tr oubleshoot ing • DHCP Server assigns IP addresses to clients • WINS Server pro vides a translation of the NetBIOS domain name to the IP address .
84 Chapter 4 Troubl eshooting NN46110-602 The client system’ s NetBIOS name must be unique in the priv ate network to which the client is connecting. Do not us e the same name as your of fice desk top machine or something like my computer . Uniqueness is required.
Chapter 4 Tr oubleshooting 85 Nortel VPN Router Tr oubleshoot ing The rene wal interval go verns ho w often a c lient must reregister its name with the WINS server . It begins trying at one-half of the renewal interv al. The extinction interv al governs the length of time betwee n when a client name is released and when it becomes extinct.
86 Chapter 4 Troubl eshooting NN46110-602 In the WINS mappings entry , enter a show database command. Note the entry for -__MSBR O WSE__. This is the machine that is actually the elected master bro w ser , and it changes frequently . If this en try is pointing to an in v alid machine, it can cause problems.
Chapter 4 Tr oubleshooting 87 Nortel VPN Router Tr oubleshoot ing T o specify a computer as the preferred master browser , set the parameter for IsDomainMasterBrowser to T rue or Y e s in the followin.
88 Chapter 4 Troubl eshooting NN46110-602 When 10.1.2.3 broadcas ts to find a network neighbor , it (incorrectly) sen ds to 10.255.255.255. Normal rou ting functionality does not fo rward such a pack et. The VPN Router finds the best match among its physical interfaces (10.
Chapter 4 Tr oubleshooting 89 Nortel VPN Router Tr oubleshoot ing After about 10 to 15 seco nds, NetBIOS gi ves up on the primary interf ac e, mov es to the correct tunnel interface, and st arts to bro wse the Network Neighborhood.
90 Chapter 4 Troubl eshooting NN46110-602 Y ou must create a connection definition fo r your initial Internet link through your service provider . A separate connection defin ition is needed for creating the PPTP tunnel.
Chapter 4 Tr oubleshooting 91 Nortel VPN Router Tr oubleshoot ing My downloaded DNS server s for m y tunnel connection do not wo r k Cause: The Microsoft Windo ws 95/98 an d W indows NT operating systems attempt to ping ne w DNS servers before addi ng them to the current list of servers.
92 Chapter 4 Troubl eshooting NN46110-602 • How to T roubleshoot TCP/IP Connectivity with W indows NT • Remote Access Service (RAS) Error Code List for W indo ws NT 4.0 • RAS Error 720 When Dialing Out • T roubleshooting PPTP Connecti vity Issues in W indo ws NT 4.
Chapter 4 Tr oubleshooting 93 Nortel VPN Router Tr oubleshoot ing • For Acti veX Scripts, Ja va , and Jav aSc ript*, you must enable both Acti veX and Jav a programs in Internet Explorer , and enable both Jav a and Jav aScript in Netscape Communicator for proper VPN Router W eb management windo ws.
94 Chapter 4 Troubl eshooting NN46110-602 Clearing y our Web br ow ser cac he when upgrading T o av oid problems when upgrading softw are revision levels, Nort el recommends that you clear your bro wser cache and exit the bro wser and all associate d windo ws (such as mail and ne w s readers).
Chapter 4 Tr oubleshooting 95 Nortel VPN Router Tr oubleshoot ing Document not found messa g e Cause: This message is returned when the HTTP ser ver ca nnot find the requested window . This can happen because th e Jav a navigation index f ile is out of synch with the rest of the system.
96 Chapter 4 Troubl eshooting NN46110-602 Action: Close help windo ws after vie wing them. Distorted backgr ound images Cause: In Netscap e versions prior to 4.0, where you configured your W ind ows 95, W indows 98, or W indo ws NT system for 8-bit color (256 colors or less), images can appe ar distorte d in the navigational area.
Chapter 4 Tr oubleshooting 97 Nortel VPN Router Tr oubleshoot ing Action: If necessary , remo ve the front bezel as described in the installation guide, then push the bottom of the po wer supply in to reseat it.
98 Chapter 4 Troubl eshooting NN46110-602 Action: Po we r-c ycle the system using the gr een p o w er button on the back of the VPN Router. Solving r outing prob lems The following sections describe routin g problems. Client address redistrib ution prob lems The number of current Utunnel host user s can display more than the configur ed maximum.
Chapter 4 Tr oubleshooting 99 Nortel VPN Router Tr oubleshoot ing Solving firewall pr ob lems An error occurred whil e par sing the policy Description: The polic y that you are attempting to view or edit cannot be opened because it does not conform to the required format.
100 Chapter 4 Troubleshoo ting NN46110-602 A uthorization failed. Please tr y again. Description: This error occurs when the wron g authentication credentials are entered. The user is re-prompted for creden tials until they are either correct or the user clicks Cancel.
Chapter 4 Troublesho oting 101 Nortel VPN Router Tr oubleshoot ing Action: T o ensure that the most current data is loaded: 1 Close the current polic y , if opened. Sa ving is not permitted until this error is remedied. 2 From the polic y selection window , select All from the Refr esh menu.
102 Chapter 4 Troubleshoo ting NN46110-602.
103 Nortel VPN Rout er Troubleshooting Chapter 5 P ac ket capture Pack et capture (PCAP) is a troubleshooting to ol that network administrators and customer support person nel use, in conjunc tion with other t ools such as statistics, logging, networ k analyzers, and testers, to remotely troubleshoot VPN Router and network problems.
104 Chapt er 5 Packet capture NN46110-602 PCAP initially occurs to the RAM b uffer . A lo w priority task writes the RAM buf fer to disk f iles, called the disk capture files. Alth ough yo u can set the maximum size of this file, when the maximum f ile size is reached, PCAP can continue writing the captured data.
Chapter 5 Packet captur e 105 Nortel VPN Router Tr oubleshoot ing • limit the traff ic that the filters capture • automatically start and stop packet capture wi th triggers Security features Pack et capture on the VPN Router prov ides the follo wing features to e nhance security: • Packet capture is disabled by default.
106 Chapt er 5 Packet capture NN46110-602 Capture types The VPN Router captures pack ets from the follo wing sources: • Physical interfaces, includi ng the following: — Asynchronous dig ital subsc.
Chapter 5 Packet captur e 107 Nortel VPN Router Tr oubleshoot ing T unnel captures sav ed to disk are encap sulated with raw IP encapsulation. When you con vert these f iles to file formats th at d o not support ra w IP encapsulation (including Snif fer), L2 encapsulation is required.
108 Chapt er 5 Packet capture NN46110-602 A global IP capture object captures pa ckets beginning from the IP header; no Layer 2 header is sav ed in the capture f ile. Because both encrypted and decrypted packets are captured, global IP packet capture is useful in trou bleshooting certain VPN issues.
Chapter 5 Packet captur e 109 Nortel VPN Router Tr oubleshoot ing •A start trigge r causes the sy stem to wait for a spe cific pack et before it starts saving pack ets to the capture buf fe r . •A stop trigger causes the system to stop saving traf fic in the capture buf fer after a specific packet matching the st op trigger is enco untered.
110 Chapt er 5 Packet capture NN46110-602 Y ou can create new capture objects un til the maximum block size reaches 25 Mbyte. (The VPN Router does no t allow you to reduce the maximum block size to less than 25 Mbyte.) If you all ocate too much memory to pa cket capture b uffe rs, you recei ve an error message suggesting a smaller buf fer size.
Chapter 5 Packet captur e 111 Nortel VPN Router Tr oubleshoot ing • Delete a capture object or capture files when you n o longer need them to free up memory or disk space. • Do not run capture objects for physical interfaces or tunnels at the sa me time that you run the glo bal IP capture object (some packets are capt ured more than once).
112 Chapt er 5 Packet capture NN46110-602 6 Enter the administrator’ s user name and password. Please enter the administrator's use r name: admin Please enter the administrator's pas sword: ***** The serial main menu appears. Main Menu: System is currently in NORMAL mode.
Chapter 5 Packet captur e 113 Nortel VPN Router Tr oubleshoot ing 10 If you want, you can now change the VPN Router administrator password . CES# configure terminal Enter configuration commands, one pe r line.
114 Chapt er 5 Packet capture NN46110-602 For e xample, enter: CES(capture-ethernet) #filepath /ideX/system/log Setting the size of the RAM buff er T o set the RAM buf fer size, from CLI Capture Configuration Mode enter: buffersize < size > where size is the size of the RAM buf fer .
Chapter 5 Packet captur e 115 Nortel VPN Router Tr oubleshoot ing For e xample, enter: CES(capture-ethernet) #maxfiles 99 Saving captured data T o set the PCAP capture mode to loss or no loss, from CL.
116 Chapt er 5 Packet capture NN46110-602 For e xample, enter the following command: CES# capture add test1 ? atm ATM interfac e capture bri Bri interface capt ure dial Dial interface cap ture FastEth.
Chapter 5 Packet captur e 117 Nortel VPN Router Tr oubleshoot ing T o conf igure a capture object: 1 Navigate to Captur e Configurati o n m o d e b y e n t e r i n g t h e capture command with the object name.
118 Chapt er 5 Packet capture NN46110-602 T unnel capture parameters Capture objects for tunnels ha ve se ve ral unique parameters. The follo wing example creates a tunnel object called bot1 , nav igates to Capture Configuration mode, and displays the co mmands for tunnel obje cts.
Chapter 5 Packet captur e 119 Nortel VPN Router Tr oubleshoot ing Global IP parameters The configurable parameters for the globa l IP capture object are the same as the parameters av ailable for physical interf ace objects.
120 Chapt er 5 Packet capture NN46110-602 In the follo wing example, the show capture command is run with no object name to display a list of all the captu re objects conf igured on the VPN Router.
Chapter 5 Packet captur e 121 Nortel VPN Router Tr oubleshoot ing Sample pac ket captu re configurations This section provides sample conf igura tions and the commands used to create them.
122 Chapt er 5 Packet capture NN46110-602 T o view the status of the running capture object, as well as its conf iguration, use the show capture command.
Chapter 5 Packet captur e 123 Nortel VPN Router Tr oubleshoot ing T o create and use this capture object, you run commands like the ones illustrated in this example. These commands do the follo wing : 1 Create a capture object called test-trigger on Fast Ethernet interface 0/1 .
124 Chapt er 5 Packet capture NN46110-602 After T elnet traff ic activ ates the stop trigger , the show capture command resembles the follo wing example.
Chapter 5 Packet captur e 125 Nortel VPN Router Tr oubleshoot ing 4 Exit Captur e Configuration mode. 5 Start the capture. CES# capture add test-remote-ip tunnel CES# capture test-remote-ip CES(capture-tunnel)# remoteip 192.
126 Chapt er 5 Packet capture NN46110-602 3 Click ether eal-setup- n.nn.n .exe . 4 Click a do wnload site and save the executable f ile on your hard dri ve. 5 Double-click the ex ecutable file to install Eth e re al software in the c:Program FilesEther eal directory .
Chapter 5 Packet captur e 127 Nortel VPN Router Tr oubleshoot ing 6 Enter the password that you entered wh en you enabled packet capture (see “Enabling packet capture on a VPN Router” on page 111 ). 7 From the open Ethereal window , disable Enable network name r esolution .
128 Chapt er 5 Packet capture NN46110-602 T1 frame relay capture: editcap -F ngsniffer d:pcapfr.cap frelay.syc 5 From Sniffer Pr o , open the .enc file or the .syc file to vie w the trace. For a global IP tra ce or tunnel trace, you must perform an extra step on Snif fer Pro because only Layer 3 traf fi c is recorded in the PCAP capture.
Chapter 5 Packet captur e 129 Nortel VPN Router Tr oubleshoot ing T o delete a pack et capture object: 1 Display all configured capture objects on the VPN Router to locate the object or objects that you w ant to delete.
130 Chapt er 5 Packet capture NN46110-602.
131 Nortel VPN Rout er Troubleshooting Appendix A MIB suppor t The VPN Router supports the management information base (MIB) for use with network management protocols in TCP/IP-based Internets and TCP/IPX-based networks. T he VPN Router supports SNMP Gets only .
132 Appendix A MIB support NN46110-602 RFC 1724—RIP V er sion 2 MIB Extension The VPN Router su pports RFC 1724, RIP V ersion 2 MIB Extension . As stated in the introduction to the RFC, the RFC “d efines a portion of the Management Information Base (MIB) for use with netw ork management protocols in TCP/ IP-based internets.
Appendix A MIB support 13 3 Nortel VPN Router Tr oubleshoot ing RFC 2787—VRRP MIB The VPN Router su pports RFC 2787, Definitions o f Managed Objects for the V irtual Router Redundancy Pr otocol . As stated i n the introduction, RFC 2787 “defines an e xtension to the Management Information Base (MIB) for use with SNMP-based network management.
134 Appendix A MIB support NN46110-602 RFC 1573—IanaIfT ype MIB This MIB contains the enumerations for rfc2233 ifT able.ifT ype. These enumerations describe the various types of interf aces that ifT able can support. RFC 2233—If MIB This MIB is the latest e volution of rfc12 13 Interf aces group, plus se veral ne w objects.
Appendix A MIB support 13 5 Nortel VPN Router Tr oubleshoot ing — hrNetworkT able — hrPrinterT able — hrDiskStorageT able hrDiskStorageCapacity — hrPartit ionT able hrPartitionSize — hrFST a.
136 Appendix A MIB support NN46110-602 RFC2863 Interface MIB ( 64 bit counter s suppor t) The support for the following entries w as a dded in the interface table: ifHCInOctets, ifHCInUcastPkts, ifHCOu tOctets and ifHCOutUcastPkts. These counters already existed and were e x tended from Counter32 to Co unter64.
Appendix A MIB support 13 7 Nortel VPN Router Tr oubleshoot ing cestraps.mib—Nor tel pr oprietar y MIB This section lists the cont ents of the cestraps.
138 Appendix A MIB support NN46110-602 -- The second means packets were dropped due to a de tected spoofed address -- The third should never happen, but means the status has been set to a bogus value.
Appendix A MIB support 13 9 Nortel VPN Router Tr oubleshoot ing new oak.mib This section provides the contents of the ne woak.mib, which defines the newoa k enterprise ID, the contivity object identif ier, and the sysObjectIDs for each VPN Router model.
140 Appendix A MIB support NN46110-602 Har dware-related traps hardwareTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 1} -- Trap #1001 hardDisk1Status OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Hard Disk Number 1 Stat us.
Appendix A MIB support 14 1 Nortel VPN Router Tr oubleshoot ing ACCESS read-only STATUS mandatory DESCRIPTION "Status of the first CPU fan." ::= {hardwareTrapInfo 6} -- Trap #1007 fanTwoStatus OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of the second CP U fan.
142 Appendix A MIB support NN46110-602 ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.5VA power." ::= {hardwareTrapInfo 12} -- Trap #10013 twoDotFiveVB OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.
Appendix A MIB support 14 3 Nortel VPN Router Tr oubleshoot ing ACCESS read-only STATUS mandatory DESCRIPTION "The chassis intrusion s ensor indicates that the unit has been opened.
144 Appendix A MIB support NN46110-602 Server-related traps serverTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 2} -- Trap #3001 radiusAcctServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of External Radi us Accounting Server.
Appendix A MIB support 14 5 Nortel VPN Router Tr oubleshoot ing ACCESS read-only STATUS mandatory DESCRIPTION "Status of DNS Server." ::= {serverTrapInfo 6} -- Trap #3007 SNMPServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of SNMP Server.
146 Appendix A MIB support NN46110-602 Software-related traps softwareTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 3} -- Trap #5001 NetBuffers OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Network buffer usage.
Appendix A MIB support 14 7 Nortel VPN Router Tr oubleshoot ing Intrusion-related traps intrusionTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 5} -- Trap #201 securityIntrusion OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Login Security Intrusion.
148 Appendix A MIB support NN46110-602 Inf ormation passed with every trap SeverityLevel OBJECT-TYPE SYNTAX INTEGER { fatal(1), major(2), minor(3), informational(4), insignificant(5), reversal(6) } ACCESS read-only STATUS mandatory DESCRIPTION "Severity of specific tr ap.
Appendix A MIB support 14 9 Nortel VPN Router Tr oubleshoot ing Ta b l e 3 provides trap categories and explanations. T able 3 T rap categories Hardware 1.3.6.1.4.1.2505.1.1.0.1001 hardDisk1StatusT rap 1.3.6.1.4.1.2505.1.1.0.1002 hardDisk0StatusT rap 1.
150 Appendix A MIB support NN46110-602 Ta b l e 4 provides descriptions for the VPN Router traps. Server 1.3.6.1.4.1.2505.1.2.0.3007 snmpServerTrap 1.3.6.1.4.1.2505.1.2.0.3008 ipAddressPoolTra p 1.3.6.1.4.1.2505.1.2.0.3009 extLDAPServerTra p 1.3.6.1.4.
Appendix A MIB support 15 1 Nortel VPN Router Tr oubleshoot ing Proprietar y 1.3.6.1.4.1.2505.1.1.0.1009 fiv eV olts P osStatusT rap Status of the +5 V olt power . Proprietar y 1.3.6.1.4.1.2505.1.1.0.10010 five V oltsMin usT rap Statu s of -5 V olt power .
152 Appendix A MIB support NN46110-602 Proprietar y 1.3.6.1.4.1.2505.1.1.0.10020 t1 WANStatusT rap S tatus of T1 W AN card(s); P ossible v a lues fo r Wanic: Aler t: Inv alid Device X. W ar ning: Device W anicX disab l ed. Aler t: Device W anicX down.
Appendix A MIB support 15 3 Nortel VPN Router Tr oubleshoot ing Proprietar y 1.3.6.1.4.1.2505.1.1.0.10022 hw AccelT rap Status of hardware accelerator card. P ossible V alues: Inv alid hardware accelerator unit %d. Unknown hardware accelerator unit %d.
154 Appendix A MIB support NN46110-602 Proprietar y 1.3.6.1.4.1.2505.1.1.0.10024 v90W AN StatusT rap Status of V .90 Interface card. P ossible V alues: Please note that X corresponds to the unit number of the card. Aler t: V .90 Inv alid index X. Disabled: De vice IntModem-X disabled.
Appendix A MIB support 15 5 Nortel VPN Router Tr oubleshoot ing Proprietar y 1.3.6.1.4.1.2505.1.1.0.10026 serUar tStatusT rap Status of Serial (COM) por t/ interface . P ossible V alues: Please note that X corresponds to the unit number of the serial interface .
156 Appendix A MIB support NN46110-602 Proprietar y 1.3.6.1.4.1.2505.1.2.0.3005 loadBala nci ngSer verT rap Status of Load Balancing Ser ver . Proprietar y 1.3.6.1.4.1.2505.1.2.0.3006 dnsSer ve rT rap Status of D NS Ser ver . Proprietar y 1.3.6.1.4.1.
Appendix A MIB support 15 7 Nortel VPN Router Tr oubleshoot ing Proprietar y 1.3.6.1.4.1.2505.1.2.0.30014 dhcp Ser verT rap Status of DHCP Ser ver . P ossible V alues: Disabled: DHCP Server is Disabled. Aler t: DHCP Ser ver is NO T configured. Aler t: DHCP Ser ver is configured and operational, Using backup config.
158 Appendix A MIB support NN46110-602 Proprietar y 1.3.6.1.4.1.2505.1.3.0.5007 sslV pnStatusT rap Status of SSL-VPN Accelerator . P ossible V alues: Disabled: Disabled—The unit is administratively disabled. Disabled: HW not installed— There is no SSL-VPN Accelerator installed.
Appendix A MIB support 15 9 Nortel VPN Router Tr oubleshoot ing Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending protoc ol entity recognizes a f ai lure in one of the communication links represente d in the agent's configuration.
160 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending protoc ol entity recognizes that one of the communicati on links represented in the agent's configuration is up . V arbind list: ifInde x—ifInde x of th e interf ace.
Appendix A MIB support 16 1 Nortel VPN Router Tr oubleshoot ing Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure n aut henticationF ailu re trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message th at is not properly authe nticated.
162 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending protoc ol entity recognizes a f ai lure in one of the communication links represente d in the agent's configuration. V arbind list: ifInde x—ifInde x of th e interf ace.
Appendix A MIB support 16 3 Nortel VPN Router Tr oubleshoot ing Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending protoc ol entity recognizes that one of the communicati on links represented in the agent's configuration is up .
164 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure An aut henticationFailure trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message th at is not properly authe nticated. The snmpEnableA uthenT raps object indicates whether this trap is generated.
165 Nortel VPN Rout er Troubleshooting Appendix B Using serial PPP Y ou use Serial Po int-to-Point Protocol (PPP) to manage the VPN Router from a remote location using PPP and the serial interface. If the VPN Router becomes unreachable ov er the Internet, you can s till dial up and mana ge it through the serial interface menu.
166 Appendix B Using serial PPP NN46110-602 Setting up a Dial-Up Netw orking connection T o establish a Serial PPP connection us ing a Microsoft Dial-Up Netw orking connection from the client system: 1 Double-click My Computer . 2 Double-click the Microsoft Di al-Up Networking icon .
Appendix B Using serial PPP 167 Nortel VPN Router Tr oubleshoot ing Setting up the modem The follo wing procedure assumes that you are using a 3Com/US Robotics 5 6 K x2 modem. It describes how to set up a modem to co mmunicate with the VPN Rou ter using a dial-up networki ng connection.
168 Appendix B Using serial PPP NN46110-602 to access all management services (HTTP , T elnet, FTP , SNMP) through the W eb interface. Once you establis h a session through PPP , the serial interface acts as a pri vate W AN interface with a n internal IP address (0.
Appendix B Using serial PPP 169 Nortel VPN Router Tr oubleshoot ing Dialing in to the VPN Router Use the standard dial-up network ing pr ocedure to connect to the VPN Router. After connecting, you can then manage th e VPN Router using either T elnet (for the command line interface) or the browser -based GUI.
170 Appendix B Using serial PPP NN46110-602 Cause: Y ou were dialed in and managing the VPN Router remotely using PPP and you changed the baud rate and applied it, bu t now you canno t manage the VPN Router. Action: T o manage the VPN Router, disconnect the dial-up co nnection and try to re-establish it.
Appendix B Using serial PPP 171 Nortel VPN Router Tr oubleshoot ing Action: Make sure that the modem that is connec ted to the VPN Router has hardware flo w control enable d. PPP option settings The follo wing settings describe the VP N Router’ s behavior when ne gotiating serial PPP .
172 Appendix B Using serial PPP NN46110-602.
173 Nortel VPN Rout er Troubleshooting Appendix C System messages System forwarding (syslog) uses the syst em logging daemon (syslogd) to forward information from the VPN Router system log to dif ferent host machines. This appendix provides a listing of possib le syslog messages that the VPN Router can write to a remote system.
174 Appendix C System messages NN46110-602 tCer t: Shutdown complete Description: This informational message indica tes that the task responsible for certificate maintenance is shut do wn. This is usually part of the normal system shutdo wn. Action: No action required.
Appendix C System messages 175 Nortel VPN Router Tr oubleshoot ing 2 Manually verify the tunnel-related ce rtificate f ingerprints. Perform this procedure any time you suspect tamperin g. ISAKMP messages ISAKMP [ 13 ] No pr oposal chosen in message from xxx (a.
176 Appendix C System messages NN46110-602 Action: Make sure the PFS settings on both sides match. Either enable PFS on the remote side, or disable PFS locally . ISAKMP [ 13 ] Err or notification (No proposal chosen) received from xxx (a.b.c.d) Description: The proposal made b y the local VPN Router is reject ed by a VPN Client.
Appendix C System messages 177 Nortel VPN Router Tr oubleshoot ing ISAKMP [ 13 ] Error notification (A uthent ication failure) received from xxx (a.b.c.d) Description: A VPN Client attempted to connect , b ut the user supplied the wrong password. Action: Make sure that the user and the VPN Router ha ve the same password.
178 Appendix C System messages NN46110-602 ISAKMP [ 13 ] In valid ID inf ormat ion in message from xxx (a.b.c.d) Description: One side of the connec tion is conf igured to support dynamic routing while the other side is conf igured for static routing.
Appendix C System messages 179 Nortel VPN Router Tr oubleshoot ing Action: Remov e the existing static route or change the route for the remote network to be a sub set or superset of the static route. SSL messages Checking c hain: in valid parent cert, xxx Description: The gi ven certif icate in the chain is not v a lid.
180 Appendix C System messages NN46110-602 No matching trusted CA certs Description: None of the certificates in the ch ain are trusted CA certificates. Y ou can receiv e this message if the CA certificat e is not installed or is not mark ed as trusted on the VPN Router.
Appendix C System messages 181 Nortel VPN Router Tr oubleshoot ing Action: Make sure the ba ckup file has an 8.3 file name. LDIF file: could not restore xxx Description: The internal LD AP se rver database cannot be restored from the specified LDIF f ile.
182 Appendix C System messages NN46110-602 CaA uthSer verCollection: authenticate xxx cer t [xxx] in valid signature b y [xxx] - xxx Description: The certif icate passed in with th e authentication request does not ha ve a v alid signature, based on the CA ce rtificate conf igured on the VPN Router.
Appendix C System messages 183 Nortel VPN Router Tr oubleshoot ing Action: Start the LD AP server , or change the external LD A P server conf iguration to make it accessible. Security: store ne w system subnet mask xxx failed— xxx Description: The system subnet mask cannot be stored in the VPN Router confi guration LD AP entry .
184 Appendix C System messages NN46110-602 Action: Start the LD AP server , or change the external LD A P server conf iguration to make it accessible. Error deleting entry [xxx]—xxx Description: An er ror occurred while deleting an LD AP entry . This indicates that the LD AP server is not accessible.
Appendix C System messages 185 Nortel VPN Router Tr oubleshoot ing xxx xxx being referenced b y xxx Description: The LDAP entry is referenced b y another LD AP entry (for example, a filter set referenced by a User Group or Branch Of fice Connection). Action: Remov e all references to the LD AP entry in question, then delete the entry .
186 Appendix C System messages NN46110-602 Session: xxx[xxx]:xxx xxx auth method not allowed Description: The authentication method of the in coming request is not allo wed in the group that th e session is bound to.
Appendix C System messages 187 Nortel VPN Router Tr oubleshoot ing Session: xxx[xxx] : xxx IP address assignment failed Description: An address cannot be assigned to the session. This occurs if the static address for the session is in use or if the address po ol is exha usted.
188 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx account not allowed now Description: The session request is outside the permitted hours of access. Action: Change the Access Hours setting assigned to the group on the Prof iles > Groups > Edit > Connecti vity window .
Appendix C System messages 189 Nortel VPN Router Tr oubleshoot ing Session: xxx[xxx] : xxx in valid pass wor d—master admin authentication failed Description: The primary administrator passw ord is in valid. This results from using the wrong passw ord or from making a mistake while typin g the password.
190 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx pool address [xxx] already in use Description: The returned static pool address is currently is use. This error occurs if another tunnel is using this address through a static address conf iguration or another address pool.
Appendix C System messages 191 Nortel VPN Router Tr oubleshoot ing RADIUS accounting messages RADIUS: Cannot send ac counting request to < ser ver-name >, possibl y due to DNS translation failure Description: This message indicates a conn ection failure.
192 Appendix C System messages NN46110-602 RADIUS: network soc ket failure with < ser ver-name >, recvfr om error: < error > Description: This message indicates a connection failure. An error occurred while receiving the response. Action: Retry authentic ation attempt and verify that RADIUS serv er packets ar e properly formed.
Appendix C System messages 193 Nortel VPN Router Tr oubleshoot ing Action: Retry authentic ation attempt and verify that RADIUS serv er packets ar e properly formed. Unsuppor ted response type (< numb er >) received from server Description: This message indicates that an in v a lid response was recei ved.
194 Appendix C System messages NN46110-602 RADIUS authentication messages RADIUS: Cannot sen d request to < ser ver-name >, possib ly due to DNS translation failure Description: This message indicates a conn ection failure. While sending a request, an error occurred du e to a socket creation probl em.
Appendix C System messages 195 Nortel VPN Router Tr oubleshoot ing RADIUS: < server-name > server timed out authenticating < user-name > Description: This message indicates a connec tion failure. The connection timed out while waiting for a response.
196 Appendix C System messages NN46110-602 RADIUS: < server-name > sent in v a lid response packet f or < user-name > Description: This message indicates that an in v a lid response was recei ved. The length of the response packet is not equal to the number of bytes recei ved.
Appendix C System messages 197 Nortel VPN Router Tr oubleshoot ing Action: V erify that the shared secrets match. RADIUS: < server-name > sent pac ket with inv alid response authenticator f or < user-name > Description: This message indicates that an in v a lid response was recei ved.
198 Appendix C System messages NN46110-602 RADIUS: < user-name > access DENIED b y ser ver < server-name > Description: This message indicates that a v a lid ac cess-reject response was receiv ed. Action: No action required. Response OK Description: This message indicates that a valid access-accept response was receiv ed.
Appendix C System messages 199 Nortel VPN Router Tr oubleshoot ing Action: No action required. Closing OSPF-RTM connection Description: OSPF closed the R TM connection, wh ich occurs if the administrator disables OSPF from Routing > OSPF window . Action: No action required.
200 Appendix C System messages NN46110-602 Can not accept x.x. x.x as router id Description: OSPF can not accept the gi ven router ID in the Routing > OSPF windo w . Action: Y ou m ust change router ID in the Routing > OSPF window . In valid router IDs are 127.
Appendix C System messages 201 Nortel VPN Router Tr oubleshoot ing VR xxx : Star ting xxx as Bac kup for xxx Description: Logged when starting as a backup for an address. The parameters are: • The VRID of this VR • The reason for starting, either because it was enabled or the interface went up • The IP addre ss Action: No action required.
202 Appendix C System messages NN46110-602 Unable to get conf iguration for VR xxx Description: This is an error e vent that is lo gged when VRRP is enabled but the common configuration parameters are mi ss ing. These are the items set in the Routing > VRRP windo w .
Appendix C System messages 203 Nortel VPN Router Tr oubleshoot ing RIP xxx : Circuit xxx deleted Description: Logged when the RIP circuit is de leted. The parameter stands for circuit ID. Action: No action required. RIP xxx : Unable to register with UDP Description: Logged when you can n ot re gister with UDP protocol.
204 Appendix C System messages NN46110-602 RIP xxx : Unable to spa wn timer task xxx fo r RI P Description: Logged when RIP fails to spa w n the timer task.
Appendix C System messages 205 Nortel VPN Router Tr oubleshoot ing Interface [ nnn ] replaced, deleting from config Description: This indicates the card type specif ied in the configuration f ile does not match the card currently in the sl ot. The interface is deleted from the confi guration.
206 Appendix C System messages NN46110-602.
207 Nortel VPN Rout er Troubleshooting Appendix D Configuring f or interoperability This chapter expl ains the requirements and procedures for setting up dif ferent vendor hardw are or software to intero perate with the VPN Router. Y ou can use these instructions to establish encrypted tunnels to and from the VPN Router with the noted v endors.
208 Appendix D Config uring for in teroperability NN46110-602 Figure 11 VPN Router and Cisco 2514 netw or k topolog y.
Appendix D Configurin g for interoperability 209 Nortel VPN Router Tr oubleshoot ing The follo wing is a show config command: Cisco2514# show config Using 1088 out of 32762 bytes version 11.3 no service password-encryption hostname Cisco2514 enable secret 5 $1$aSJB$Xz/o4I4IqCY.
210 Appendix D Config uring for in teroperability NN46110-602 dialer-list 1 protocol ipx permit snmp-server community public RO line con 0 line aux 0 line vty 0 4 password terminal login end Configuri.
Appendix D Configurin g for interoperability 211 Nortel VPN Router Tr oubleshoot ing Configuring the SafeNet/Soft-PK Security P olicy Database Editor , V ersion 1.
212 Appendix D Config uring for in teroperability NN46110-602 Connecting to IRE SafeNET/So ft-PK Security P olic y Client T o set up the VPN Router to establish encrypted tunnel connections with the IRE SafeNet/Soft-PK Security Polic y Client, do the following: 1 Open the SafeNet/Soft-PK Secu rity Policy Client, and click File: New .
Appendix D Configurin g for interoperability 213 Nortel VPN Router Tr oubleshoot ing • 8.1.10.42 The SafeNet/Soft PX Security Po lic y Editor dialog box appears. 6 Click My Identity to conf igure the SafeNet clie nt, and select the following: • Select Certificate: None •I D T y p e : IP Address • Port: All 7 Click Pr e-Shared K ey .
214 Appendix D Config uring for in teroperability NN46110-602 The SafeNet/Soft-PK Security Po lic y Editor dialog box appears. 10 From Security Policy: Select Phase 1 Negotiation Mode , click Main Mode .
Appendix D Configurin g for interoperability 215 Nortel VPN Router Tr oubleshoot ing • Authentication Method: Pre-S hared key • Encrypt Alg: DES •H a s h A l g : MD5 •S A L i f e : Seconds and.
216 Appendix D Config uring for in teroperability NN46110-602 9 For some v e ndors, if you want to turn off V endor ID and/or P erfect F o rward Secrecy (PFS) , do that on the Profiles > Gr oups > IPsec: Configur e window .
Appendix D Configurin g for interoperability 217 Nortel VPN Router Tr oubleshoot ing Considerations f o r usin g third- par ty c lients There are sev era l considerations regarding the use of third-pa.
218 Appendix D Config uring for in teroperability NN46110-602 • Load Balancing—T raditional load balancers often do not work with the IPsec protocol because of the security featur es on individual packets and separate ke y management and data channels.
Appendix D Configurin g for interoperability 219 Nortel VPN Router Tr oubleshoot ing (are correctly decrypted, and authenti cated) are accepted; other packets are dropped. If an y attempt is made to chan ge the station address of the client, the tunnel is automatically closed.
220 Appendix D Config uring for in teroperability NN46110-602 then select a default server certif icate from the list. Y ou conf igure servers from the System > Certif icates window . 7 Select Prof iles > Branch Off ice , click Edit , scroll do wn to the IPsec section and click Configur e .
Appendix D Configurin g for interoperability 221 Nortel VPN Router Tr oubleshoot ing Figure 13 Split tunneling e xample T o configure the VPN Router as a user tunnel: 1 Select Prof iles > Groups and click Add . Enter a group n ame of up to 64 characters (spaces are pe rmitted); for example, Research and De velopment.
222 Appendix D Config uring for in teroperability NN46110-602 6 Selections in the Encryption fields are dependent on the type of encryption that your third-pa rty client supports. 7 Enable Perfect F orwar d Secrecy (PFS) . PFS ensures that if one ke y is compromised, subsequent keys are not compromised.
Appendix D Configurin g for interoperability 223 Nortel VPN Router Tr oubleshoot ing Network addresses form th e basis of the IPX internetwork addressing scheme for sending packets between netw ork segm ents.
224 Appendix D Config uring for in teroperability NN46110-602 Windows 95 and Windo ws 98 When running Windo ws 95 or W in dows 98, load the intraNetW are* client, which is a vailable from the No vell W eb site: http://www.
Appendix D Configurin g for interoperability 225 Nortel VPN Router Tr oubleshoot ing Figure 14 IPX topolog y Note: The pri vate LAN can also carry IP and IPX traf fic simultaneously .
226 Appendix D Config uring for in teroperability NN46110-602.
Nortel VPN Rout er Troubleshooting 227 Inde x A accounting data 40 records 38, 39 accounting log 38 acti ve sessions 96 Acti veX Scripts 93 administrator settings 28 administrator privileges 27 authen.
228 Index NN46110-602 SSL 179 e vent log 35, 41 External DHCP server 97 extinction interval 84 timeout 84 Extranet Access client monitor 70 connection problems 73 F factory default 49 configuration 50.
Index 229 Nortel VPN Router Tr oubleshoot ing modem hardware errors 82 MS-DOS naming con vention 97 multiple Help windows 95 N NetBEUI 77, 83 NetBIOS 77, 83, 84, 88 Netscape Communicator 92 netstats command 71 NetW are client 224 Network Neighborhood 84 new oak.
230 Index NN46110-602 RADIUS accounting 191 RADIUS authentication 194 routing 198 security 181 SSL 179 T T1/V .35 interface 80 technical publications 22 text con ventions 17 tools ARP 30 ping 29 trace.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Nortel Networks NN46110-602 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Nortel Networks NN46110-602 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Nortel Networks NN46110-602, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Nortel Networks NN46110-602 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Nortel Networks NN46110-602, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Nortel Networks NN46110-602.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Nortel Networks NN46110-602. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Nortel Networks NN46110-602 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.