F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices VPN Configuration Guide-6PW100
405
Start time: 2010-12-21 17:00:06 TTL: 52s
Root Zone(in):
Zone(out): Management
Received packet(s)(Init): 1 packet(s) 77 byte(s)
Received packet(s)(Reply): 2 packet(s) 183 byte(s)
Initiator:
Source IP/Port : 0006::0002/32768
Dest IP/Port : 2000:0:0404:0402::/44012
VPN-Instance/VLAN ID/VLL ID:
Responder:
Source IP/Port : 4.4.4.2/0
Dest IP/Port : 6.6.6.10/12299
VPN-Instance/VLAN ID/VLL ID:
Pro: ICMPv6(58) App: unknown State: ICMP-CLOSED
Start time: 2010-12-21 17:00:06 TTL: 23s
Root Zone(in): Management
Zone(out): Management
Received packet(s)(Init): 5 packet(s) 520 byte(s)
Received packet(s)(Reply): 5 packet(s) 420 byte(s)
Total find: 2
84B
Troubleshooting AFT
292BSymptom 1
When an IPv6 host with a non-IVI address initiates communication with an IPv4 host, AFT fails to perform
address translation.
293BSolution
1. Enable debugging for AFT and locate the causes based on the debugging information.
2. Verify the translation of the source address is successful based on the debugging information. If not,
the address pool might run out of IP addresses.
3. You can configure a larger address pool or use IP address + port number translation to save the IP
addresses in the address pool.
294BSymptom 2
When an IPv6 host with an IVI address initiates communication with an IPv4 host, AFT fails to perform
address translation.
295BSolution
Verify the IVI address complies with the IVI address format. If not, change the address of the IPv6 host or
configure a 6to4 AFT policy.