User's Manual

Chapter 21 Logs
NBG-460N User’s Guide
284
Rule [%d] phase 1 mismatch The listed rule’s IKE phase 1 did not match between
the router and the peer.
Rule [%d] phase 2 mismatch The listed rule’s IKE phase 2 did not match between
the router and the peer.
Rule [%d] Phase 2 key length
mismatch
The listed rule’s IKE phase 2 key lengths (with the
AES encryption algorithm) did not match between the
router and the peer.
Table 105 PKI Logs
LOG MESSAGE DESCRIPTION
Enrollment successful The SCEP online certificate enrollment was successful. The
Destination field records the certification authority server IP
address and port.
Enrollment failed The SCEP online certificate enrollment failed. The Destination
field records the certification authority server’s IP address
and port.
Failed to resolve
<SCEP CA server url>
The SCEP online certificate enrollment failed because the
certification authority server’s address cannot be resolved.
Enrollment successful The CMP online certificate enrollment was successful. The
Destination field records the certification authority server’s IP
address and port.
Enrollment failed The CMP online certificate enrollment failed. The Destination
field records the certification authority server’s IP address
and port.
Failed to resolve <CMP
CA server url>
The CMP online certificate enrollment failed because the
certification authority server’s IP address cannot be resolved.
Rcvd ca cert: <subject
name>
The router received a certification authority certificate, with
subject name as recorded, from the LDAP server whose IP
address and port are recorded in the Source field.
Rcvd user cert:
<subject name>
The router received a user certificate, with subject name as
recorded, from the LDAP server whose IP address and port
are recorded in the Source field.
Rcvd CRL <size>:
<issuer name>
The router received a CRL (Certificate Revocation List), with
size and issuer name as recorded, from the LDAP server
whose IP address and port are recorded in the Source field.
Rcvd ARL <size>:
<issuer name>
The router received an ARL (Authority Revocation List), with
size and issuer name as recorded, from the LDAP server
whose address and port are recorded in the Source field.
Failed to decode the
received ca cert
The router received a corrupted certification authority
certificate from the LDAP server whose address and port are
recorded in the Source field.
Failed to decode the
received user cert
The router received a corrupted user certificate from the
LDAP server whose address and port are recorded in the
Source field.
Table 104 IKE Logs (continued)
LOG MESSAGE DESCRIPTION