N0RTELNortel Secure Router 8000 SeriesTroubleshooting - VASRelease: 5.3Document Revision: 01.01www.nortel.comN N46240-709 324767-A
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingproposal name:t^ran1The display indicates the proposal i
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASUsing local-address: {}Using interface: {Ethernet1/0/0}IP
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingYou can use the ipsec sa global-duration time-based comm
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASThe display indicates that the SPI on the inbound of SA i
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingYou can use the dh { group1 j group2 } command to modify
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASdisplay ike sanat traversal: disableThe preceding configu
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootinginput/output securi^ty bytes: 4816/5600 input/output dro
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASThe packets are sent from the interface that uses the IPS
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingTo remove this fault, you need to check whether ACLs on
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContents3 Firewall troubleshooting...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________About this documentAbout this documentOverviewThis section describes the organization o
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________FiguresFiguresFigure 3-1 Networking of the firewall...Figur
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________TablesTablesTable 3-1 Description of the output information of the display traffic pol
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________3 Firewall troubleshooting3Firewall troubleshootingAbout this chapterThe following tabl
3 Firewall troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS3.1 FirewallConceptsThe firewall of the Secure Router 8000 Ser
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________3 Firewall troubleshooting3.2.1 Networking environmentFigure 3-1 Networking of the fire
3 Firewall troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASFigure 3-2 Diagnostic flowchart for faults on the firewallFire
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________3 Firewall troubleshooting3.2.4 Troubleshooting proceduresThe troubleshooting procedur
About this documentNortel Secure Router 8000 Series_________Troubleshooting - VASChapter Description2 IPSec and IKE troubleshootingThis chapter descri
3 Firewall troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASChecking that the traffic behavior is correctRun the display t
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________3 Firewall troubleshootingCommandDescriptiondisplay traffic policy interface[ { interfa
3 Firewall troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASMain fieldDescriptionBehaviorThe behavior associated with the
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________3 Firewall troubleshootingRule(s) : if-match ac l 3001Table 3-3 Description of the outp
3 Firewall troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASTable 3-4 Description of the output information of the display
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContents4 NAT troubleshooting...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________FiguresFiguresFigure 4-1 NAT principles...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________TablesTablesTable 4-1 Description of the output information of the display firewall ser
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________About this documentCommand conventionsConvention DescriptionBoldfaceThe keywords of a c
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshooting4NAT troubleshootingAbout This ChapterThe following table lists th
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS4.1 NAT4.1.1 NAT attributesNetwork Address Translation (NAT) allow
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshooting4.1.2 NAT modesNAT has two modes. In one mode, NAT replaces only t
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS4.2 Troubleshooting NAT Troubleshooting4.2.1 Typical NetworkingNATA
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingFigure 4-4 Networking of the load balancing, flow control and BT s
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem DescriptionConfiguring the limit on the number of connected us
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingFigure 4-5 troubleshooting flowchart/ Configuring NAT 1 failsIssu
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS4.2.4 Troubleshooting proceduresThe troubleshooting procedures are
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshooting4.3 Troubleshooting cases4.3.1 Internal Network Cannot Successfu
About this documentNortel Secure Router 8000 Series_________Troubleshooting - VASMouse operationAction DescriptionClick Select and release the primary
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASStep 6 Run the display ip routing-table command to check whether a
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingA: You can configure a different public address of the NAT server
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASCommandDescriptionNotedisplay nat algDisplays information about the
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingThis output information is the aging time (in seconds) of the esta
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem DescriptionFlag The type of the servermap table0x2000: specifi
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingTable 4-2 Description of the output information of the display fir
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASdisplay nat alg[Nortel] display nat algNAT application level gatewa
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingThis output information displays the traffic control of NAT:• The
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASGlobalAddr GlobalPort Interface:Ethernet4/0/65.1.1.5 (5,3000) 21 1
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingIn addition:• Configure an internal server on the interface Ether
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContents1 AAA troubleshooting...
4 NAT troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS*0.97096416 Nortel SEC/8/ASPF:[ASPF] Packet Information:SrcAddr =0x
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________4 NAT troubleshootingItem DescriptionNatSrvInIPThe IP of the NAT server (5.1.1.5)NatSrv
Nortel Secure Router 8000 SeriesTroubleshooting - VAS___________ContentsContentsIndex...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS___________IndexIndexAAAA, 1-2 address pool, 1-4 authentication algorithm MD5, 2-5 SHA-1,2-5Cconc
IndexNortel Secure Router 8000 Series__________Troubleshooting - VASauthenticator, 1-3 code, 1-3 identifier, 1-3 length, 1-3SSA, 2-3schemes and modes
Copyright © 2009 Nortel Networks All Rights Reserved.Printed in Canada, India, and the United States of America Release: 5.3Publication: NN46240-709 D
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________FiguresFiguresFigure 1-1 RADIUS message structure...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1AAA troubleshootingAbout this chapterThe following table shows th
Nortel Secure Router 8000 Series Release: 5.3Publication: NN46240-709 Document status: Standard Document release date: 30 March 2009Copyright © 2009 N
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS1.1.1 AAA and RADIUSAAARADIUSAuthentication, Authorization, and Ac
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshootingValue Packet typeIndication Description1 Access-request Sending an
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASAfter receiving an AAA authentication or accounting message, the NA
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting• non-authentication• RADIUS authentication• HWTACACS authentic
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASConfigure the shared key on the RADIUS server template. The shared
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1.2.2 Configuration notesItem Sub-item DescriptionConfiguringseri
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS#aaaauthenticat^ion-scheme default #authorization-scheme default #a
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1.2.3 Troubleshooting flowchartFigure 1-4 Troubleshooting flowchar
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASIf PAP mode is not used, check that the PPP link is Up.# Configure
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1.3.1 Typical networkingFigure 1-5 shows the networking of RADIUS
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContentsAbout this document...
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfiguringAAAConfigure the authentication
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting[Nortel-radius-rt_nortel] quitConfiguring AAA• Create a RADIUS au
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS1.3.3 Troubleshooting flowchartFigure 1-6 Troubleshooting flowchart
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1.3.4 Troubleshooting procedureStep 1 Check that the RADIUS serve
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASThe preceding display indicates that the RADIUS authentication pack
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshootingID : 15 [Ftp-Directory ] [7 ] [hda1 :]The preceding display indica
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASCheck that the authentication port number is the same as that confi
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshooting1.5 FAQsQ: Nortel devices and non-Nortel devices use the same TACA
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS• If all the domain address pools have no address to allocate, the
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshootingValue Attributes Field format Usage15 Login-Service Integer Indica
2.2 Troubleshooting manual IPSec SA setup... 2-62.2.1
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASValue Attributes Field format Usage43 Acct-Output-OctetsIntegerIndi
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshootingCommandDescriptiondisplay domainDisplays the domain.display radius
1 AAA troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASdisplay domain<Nortel> display domain nortelDomain-name : n
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________1 AAA troubleshootingSource-IP-address : 0.0.0 .0Shared-key : nortelQuiet-interval(mi
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContents2 IPSec and IKE troubleshooting...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________FiguresFiguresFigure 2-1 Format of the transport mode packets...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2IPSec and IKE troubleshootingAbout this chapterThe foll
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASSection Description2.8 FAQs This section lists frequently
4.1.1 NAT attributes...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.1 IPSec and IKE overviewThe IP Security (IPSec) protoc
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASIPSec encapsulation modesThe SA specifies the protocol en
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting- Message Digest 5 (MD5) enters a message of any length
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASMain mode: Isolates the shared key exchange from the auth
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingItem Sub-item DescriptionConfigure the source and destin
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the SPIs of SAsConfigu
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingItemConfiguring the IPSec policy group applicationSub-it
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASConfiguring an IPSec policy# Configure the name of the IP
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.2.3 Troubleshooting flowchartFigure 2-4 Troubleshootin
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS2.2.4 Troubleshooting procedureStep 1 Check whether two e
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingIPsec Policy Group: "map1"Using local-address:
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS<RouterA> display ipsec sa policy map1Interface: Et
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingFigure 2-5 Networking diagram of setting up ISAKMP IPSec
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the encryption algorit
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingItem Sub-item DescriptionConfigure the IKE proposal IDIn
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure PFS PFS is enabled in
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting[RouterA-ike-peer-routerb] remote-address 202.38.162.11.
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASFigure 2-6 Troubleshooting flowchart of SA setup in Phase
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingFigure 2-7 Troubleshooting flowchart of SA setup in Phas
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASUse the display ike sa command to view SAs in Phase 1.<
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________FiguresFiguresFigure 1-1 RADIUS message structure...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting<RouterA> display ipsec sa policy map1Interface: E
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASdropped securi^ty packet detai^l^: no enough memory : 0 c
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingFigure 2-8 Networking diagram of setting up SA using an
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the authentication mod
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingItem Sub-item DescriptionConfigure the peer The name is
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the sequence number of
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingConfiguring an IPSec proposal# Configure the name of the
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS2.4.3 Troubleshooting flowchartFigure 2-9 Troubleshooting
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.4.4 Troubleshooting procedureStep 1 Check whether two
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASIPsec policy name: "map1" sequence number: 10 m
FiguresFigure 4-1 NAT principles...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.5.1 Typical networkingFigure 2-10 shows the networking
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItemConfiguring the local ID for IKEConfiguring the IPSec
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingItem Sub-item DescriptionApplying the IPSec policy group
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the IP addresses or ad
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting# Configure the host local ID in aggressive IKE negotiat
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASRouter B[RouterA-Ethernet1/2/0] ipsec policy map1For info
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting[RouterB-ipsec-policy-templet^-maptemp-10] ike-peer rout
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS2.5.3 Troubleshooting flowchartFigure 2-11 Troubleshootin
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.5.4 Troubleshooting procedureStep 1 Check whether two
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASUse the display ipsec proposal name command to view if th
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________ContentsContentsAbout this document...
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingFigure 2-12 Networking diagram of configuring IPSec Rout
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASItem Sub-item DescriptionConfigure the number of ACL rule
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting[RouterA-Tunnel^1/0/1] destination 202.38.162.1Configuri
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS2.6.3 Troubleshooting flowchartFigure 2-13 Troubleshooti
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshooting2.6.4 Troubleshooting procedureStep 1 Check whether the
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS2.7 Troubleshooting casesFault symptomFigure 2-14 shows
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingSummaryIf the keep-alive function of ISAKMP SA is disabl
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VAS• The local and remote ACLs must be mutually mirrored. (
Nortel Secure Router 8000 SeriesTroubleshooting - VAS__________2 IPSec and IKE troubleshootingCommandDescriptiondisplay ipsec sa policyDisplays the SA
2 IPSec and IKE troubleshootingNortel Secure Router 8000 Series_________Troubleshooting - VASUsing local-address: {}Using interface: {Ethernet0/2/0}IP
Comments to this Manuals