Instruction/ maintenance manual of the product NN46110-602 Nortel
Go to page of 230
Version 7.00 Part No. NN4611 0-602 315900-E Rev 01 February 2007 Document status: Standard 600 Technology Park Drive Billerica, MA 01821-4130 Nor tel VPN Router T r oub leshooting.
2 NN46110-602 Copyright © 2007 Nortel Ne tworks. All rights reserved. The information in this document is subj ect to change without notice. The statements, config urations, technical data, and recommendations in this docume nt are believ ed to be accura te and reliable, but are presen ted without e xpress or implied warranty .
3 Nortel VPN Router Tr oublesho oting Portions of the code in this softw are product may be Copyright © 1988, Re gents of the Univ er sity of California.
4 NN46110-602 3. Limitation of Remedies. IN NO EVENT SHALL NOR TEL NETWORKS O R ITS A GENTS OR SUPPLIERS BE LIABLE FOR ANY OF THE FOLLO WING: a) DAMA GES B A SED ON ANY THIRD P AR TY CLAIM; b) LOS S O.
5 Nor tel VPN Router T roublesh ooting Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Bef ore you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
6 Contents NN46110-602 Configuring SNMP traps t o send notification when an IP address pool reaches the configured threshold . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Chapter 2 Status and logging . .
Contents 7 Nor tel VPN Router T roublesh ooting Using SFTP to transfer back up files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Stopping th e transf er of b ack up files u sing SFTP . . . . . . . . . . . . . . . . . . . . . . 59 Disabling new logins .
8 Contents NN46110-602 System pr oblems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96 Solving routin g problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Contents 9 Nor tel VPN Router T roublesh ooting Viewing a pack et c apture out put file on a PC . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 Installing Ethereal software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
10 Contents NN46110-602 Appendix B Using serial PPP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165 Establishing a serial PPP connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Contents 11 Nor tel VPN Router T roublesh ooting IPX client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Windows 95 and Win dows 98 . . . . . . . . . . . . . . . . . . . . . . . . . .
12 Contents NN46110-602.
13 Nor tel VPN Router T roublesh ooting Figures Figure 1 Admin > SN MP T raps window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Figure 2 Event logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14 Figures NN46110-602.
15 Nor tel VPN Router T roublesh ooting Ta b l e s T able 1 Field IDs for data collection records . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 T able 2 T roubleshooting t ools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
16 Tables NN46110-602.
17 Nortel VPN Ro uter Trouble shooting Preface This guide prov ides information about ho w to manage and troubleshoot the Nortel VPN Router . Bef o re y ou begin This guide is for network managers wh o monitor and mainta in the Nortel VPN Router .
18 Pref ace NN46110-602 braces ({}) Indicate required elements in syntax descriptions where there is more than one optio n. Y ou must ch oose only one of the options.
Preface 19 Nortel VPN Router Tr oublesho oting Acr o n yms This guide uses the follo wing acronyms: vertical line ( | ) Separates choices for command keywords and arg uments. Enter only one of the cho ices. Do not type the vertical line when entering the command.
20 Pref ace NN46110-602 L2TP Layer 2 T unneling Protocol LAN local area network LD AP Lightweight Directory Access Proto col N A T Network Address T ranslation OSI Open Systems Interconnection OSPF Op.
Preface 21 Nortel VPN Router Tr oublesho oting Related publications For more information about the Nort el VPN Router , see the following publications: • Release notes pro vide the latest inform ation, including brief descriptions of the ne w features, problems f ixed in th is release, and kno wn problems and workarounds.
22 Pref ace NN46110-602 Har d-copy tec hnical manuals Y ou can print selected technical manuals and release notes free, directly from the Internet. Go to www .nortelnetworks.com/documentation , find the product for which you need documentation, then lo cate the specif ic category and model or version for your har dware or software p roduct.
Preface 23 Nortel VPN Router Tr oublesho oting Getting help fr om the Nor tel W eb site The best way to get techni cal support for Nortel products is from the Nortel T echnical Support W eb site: www .nortel.com/support This site provides quick access to softw are, documentation, bulletins, and tools to address issues with Nortel prod ucts.
24 Pref ace NN46110-602 Getting help thr ough a Nor t el distributor or reseller If you purchased a service contract for you r Nortel product from a distrib utor or authorized reseller , contact the technica l support staf f for that distrib u tor or reseller .
25 Nortel VPN Ro uter Trouble shooting Ne w in this release The follo wing section details what is new in Nortel VPN Router T r oubleshooting for Release 7.
26 New in this release NN46110-602 A utomatic backups Y ou can no w back up a file or a directory , as well as trigger a backup, when a file changes. Previously , you could only back up system, configuration, and log files. Y ou can use either the graphical user interface (GUI) or the command line interface (CLI) to conf igure automated backup.
27 Nortel VPN Ro uter Trouble shooting Chapter 1 VPN Router administration This chapter introduces administrator se ttings, tools, system conf iguration, and f ile management. It also include s informat ion about SNMP traps. Administrator settings The VPN Router supports multiple administ rators.
28 Chapter 1 VPN Router ad ministration NN46110-602 Y ou use the Administrator Settin gs windo w to do the following: • change the primary ad ministrator user ID an d password • control the Admini.
Chapter 1 VPN Router administration 29 Nortel VPN Router Tr oublesho oting Dynamic pass w ord T wo types of administra tiv e use rs exist on the VPN Router: • one super -user (Administrator) • as many administrati ve users as needed There is dynamic password support fo r administrati ve users only .
30 Chapter 1 VPN Router ad ministration NN46110-602 The T race route tool measures a network ro und-trip delay . Messages are sent per hop and the w ait occurs between each message. If the address is unreachable, it uses the follo wing formula to determin e ho w long it takes for the T raceroute to time out.
Chapter 1 VPN Router administration 31 Nortel VPN Router Tr oublesho oting Simple Netw ork Management Protocol (SNMP) Use the Admin > SNMP window to do the follo w ing: • designate the remote SNM.
32 Chapter 1 VPN Router ad ministration NN46110-602 The traps displayed on the group window s—in particular the Hardware T rap Conf iguration and the Service T rap Conf iguration windows—reflect the hardw are and software av ailable on your VPN Router.
Chapter 1 VPN Router administration 33 Nortel VPN Router Tr oublesho oting Figure 1 Admin > SNMP T raps windo w 2 Enter a host name o r IP address in the Ho st Name or IP Addr ess text box. 3 Enter a name in the Community Name te xt box. 4 Click Enable .
34 Chapter 1 VPN Router ad ministration NN46110-602 T o configure the amount: CES(config)# ip local pool ex hausted-amount <amount>.
35 Nortel VPN Ro uter Trouble shooting Chapter 2 Status and logg ing The Status windo ws sho w which users are logged on, their traff ic demands, and a summary of the VPN Router’ s hardware configurat ion, including a v ailable memory and disk space.
36 Chapter 2 Status and logging NN46110-602 Most e vents are sent to the e vent log f irs t. Significant e vents from the e vent log are sent to the system log.
Chapter 2 St atus and logging 37 Nortel VPN Router Tr oublesho oting If you ha ve multiple VPN Routers throughou t the world, use the Greenwich Mean T ime (GMT) standard to synchronize the v arious log files so that the timestamps are directly comparable.
38 Chapter 2 Status and logging NN46110-602 Accounting The accounting log provides informatio n about user sessi ons. This log pro vides last and first names, user ID, tunnel ty pe, session start and end dates, and the number of packets and b ytes transferre d.
Chapter 2 St atus and logging 39 Nortel VPN Router Tr oublesho oting The data collection system stores records in te xt-bas ed files stored in the system/ dclog subdirectory . The system stores the most recent 60 days of data. The system stores daily files, summary files, and summary history f iles.
40 Chapter 2 Status and logging NN46110-602 • Summary file that al ways has exactly f i ve records containing summary data in a f ile called summary .
Chapter 2 St atus and logging 41 Nortel VPN Router Tr oublesho oting Logs The VPN Router has se veral logs that prov ide dif ferent le vels of information. The logs are stored in te xt files and indicate what happened, when the e vent occu rred, and the IP address and user ID of the person causing the e vent.
42 Chapter 2 Status and logging NN46110-602 As the e vent log adds inform ation, the oldest entries are o verwritten. The e vent log retains the latest 2000 entries and dis cards old entries when it is refreshed. T o configure e vent logging: 1 Select Status > Even t Log .
Chapter 2 St atus and logging 43 Nortel VPN Router Tr oublesho oting Figure 3 Capture an d display filters 5 Y ou conf igure the capture f ilter and di splay filter using Entity-Subentity or Se verity . T o configure the capture f ilter or display fi lter: a Click Conf igure Captur e Entity or Configur e Display Entity .
44 Chapter 2 Status and logging NN46110-602 Figure 4 Configure Display Entity b Select an Entity from the list. c Select a Subentity from the list. d Click Add to add the selected entity-s ubentity pair to the f ilter . e Click Accept to complete your changes to the filter .
Chapter 2 St atus and logging 45 Nortel VPN Router Tr oublesho oting System log The system log contains all system ev ents that are considered significant enough to be written to disk, including those disp layed in the conf iguration and security logs.
46 Chapter 2 Status and logging NN46110-602 • communications with servers •L D A P • Remote Authentication Dial-In User Service (RADIUS) Configuration log The Conf iguration log records all conf iguration changes.
47 Nortel VPN Ro uter Trouble shooting Chapter 3 Administrative tasks This chapter describes administrativ e task s that help you operate the VPN Router. These tasks provide details on scheduling backup s, upgrading the software image, saving conf iguration files, performing f ile maintenance, creating recov ery diskettes, and system shutdo wn.
48 Chapter 3 Administrative tasks NN46110-602 Reco ver y In the unlikely e vent that there is a hard disk crash, use the Reco very windo w to configure a reco very diskette to restore the software image and f ile system to the hard dri ve of the VPN Router.
Chapter 3 Administrative tasks 49 Nortel VPN Router Tr oublesho oting This supplies a minimal conf iguration u tility so that you can vie w the VPN Router from a W eb browser . 3 In the W eb bro wser , enter the management IP address of the VPN Rou ter.
50 Chapter 3 Administrative tasks NN46110-602 • Select Restor e Factory Conf iguration , then cli ck Restor e to return the VPN Router to its original factory def ault co nfiguration. This erases da ta contained in flash memory and also in the configuration f ile.
Chapter 3 Administrative tasks 51 Nortel VPN Router Tr oublesho oting Y ou can use a ne w factory default softw a re image and f ile system to restore the VPN Router’ s hard disk. Specify the name or address and path of th e network f ile server ont o which the softwa re from the Nortel CD is installed.
52 Chapter 3 Administrative tasks NN46110-602 12 Click Synchr onize to immediately syn chronize the primary and second ary disks. Thereafter , the disks auto matically synchronize e very hour . 13 From the list, select the driv e on which you want to upgrade the system boot software.
Chapter 3 Administrative tasks 53 Nortel VPN Router Tr oublesho oting Y ou must create a directory on the File T ransfer Protocol (FTP) or Secure File T ransfer Protocol (SFTP) server before running automatic backup.
54 Chapter 3 Administrative tasks NN46110-602 T o enable automatic backup when a file or a directory changes: 1 Select Admin > A uto Backup . The Automatic Backup window appears. (Figure 6) Figure 6 A utomatic ba ckup window 2 Click Enabled to enable the associated host backup file serv er .
Chapter 3 Administrative tasks 55 Nortel VPN Router Tr oublesho oting 7 T o back up at certain interv als of time, click Interval and in the Interv al text box specify in hours the time peri od af ter which the system automatically backs up changed files.
56 Chapter 3 Administrative tasks NN46110-602 Figure 7 Specific A utomatic Back up window 14 T o see the list of f iles for a directory , highlight the name of a d irectory and click Display .
Chapter 3 Administrative tasks 57 Nortel VPN Router Tr oublesho oting 22 Click Backup to run the backup to each enabled server no w . This action also synchronizes the hard disk dri ves when there is more than one hard driv e in a de vice. Otherwise, the hard disk s synchronize automa tically ev ery 60 minutes.
58 Chapter 3 Administrative tasks NN46110-602 Backing up specific f iles and directories T o back up specific f iles and dire ctories, with the option to delete them after backup, e nter: exception ba.
Chapter 3 Administrative tasks 59 Nortel VPN Router Tr oublesho oting Stopping the bac kup of changes to specific files or directories T o stop backing up the chan ges for specif ic files or directori.
60 Chapter 3 Administrative tasks NN46110-602 Disabling ne w logins Y ou can pre vent clients from connecting to the VPN Router without affecting the users currently connected b y using this feature to disable ne w logins. When ne w logins is disabled, no ne w IP se c connections are established.
Chapter 3 Administrative tasks 61 Nortel VPN Router Tr oublesho oting • Nortel W eb site • your o wn FTP site if you previously do wnloaded the software from the Nortel FTP site • Nortel software CD If an FTP serv er does not use standard FTP por t numbers, you cannot use it to do wnload FTP servers for Nortel softw are .
62 Chapter 3 Administrative tasks NN46110-602 Before you upgrade your softwa re, use one of the follo wing methods to make sure there is enough av ailable disk space: • From the GUI, select Status > Statistics > File System . The last line lists the free space on the disk.
Chapter 3 Administrative tasks 63 Nortel VPN Router Tr oublesho oting 5 Ty p e 5 ( Create A User Control Tunnel (IPsec) Profile ). 6 Enter the user ID that you plan to use to log in remotely to the VPN Router . 7 Enter the password that you plan to use.
64 Chapter 3 Administrative tasks NN46110-602 b Click Backup to start the backup immediately . This sav es your entire hard dri ve, incl uding the LD AP and configuration f iles. Retrieving the ne w software For V ersion 4.80 and later , the VPN Ro uter release image is av ailable in a compressed .
Chapter 3 Administrative tasks 65 Nortel VPN Router Tr oublesho oting Figure 9 sho ws an example upgrade to V04_80.114 from server 192.32.250.64. The f ile V04_80.114.tar .gz must be located at the root of the FTP directory . Figure 9 FTP menu e xample When you FTP to the FTP serv er from another PC, you see the location of the file.
66 Chapter 3 Administrative tasks NN46110-602 • User ID: type the login ID required to gain access to the FTP server where the ne w VPN Router software is located. • Passw ord and Confirm Passw o rd: type the password (twice) that corresponds to the user ID you just entered.
Chapter 3 Administrative tasks 67 Nortel VPN Router Tr oublesho oting — Response Timeout f or RADI US Accounting Server — Exter nal RADIUS Accounting Serv er b Click OK . Applying the software After you start the apply p rocess, do not make any queri es on the VPN Router.
68 Chapter 3 Administrative tasks NN46110-602 6 Select a system shutdo wn type of None and cl ick OK . Y ou hav e su ccessfully upgraded yo ur switch..
69 Nortel VPN Ro uter Trouble shooting Chapter 4 T r oubleshooting This chapter introduces the concepts and practices of advanced network configuration and troubleshooting fo r the Nortel VPN Router.
70 Chapter 4 Troub leshooting NN46110-602 T roubleshooting remote access problems typica lly starts at the client end when the remote user cannot establish a connection, loses a connection, or has dif ficulty bro wsing the network or printing.
Chapter 4 Troubleshooting 71 Nortel VPN Router Tr oublesho oting Microsoft Point-to-Point T unneling Pr oto col (PPTP) Dial-Up Ne tworking Monitor provides network statistics on device, connection, and network protocols that help monitor traf fic flo w and a ssess PPTP connection performance.
72 Chapter 4 Troub leshooting NN46110-602 Solving connectivity pr oblems This section lists man y of the common co nnecti vity problems that occur and their recommended so lutions.
Chapter 4 Troubleshooting 73 Nortel VPN Router Tr oublesho oting 1 Confirm that the modem is attached and working properly by running a terminal emulation program at thei r remote workstation, such as, Hyperterminal*, and issuing the A T command. If the response is AT O K , the modem is operating correctly .
74 Chapter 4 Troub leshooting NN46110-602 Remote host not responding Cause: This indicates that the VPN Router ne ver respon ded to the IPsec connection attempt or that User Datagram Protocol (UDP) port 500 is blocke d.
Chapter 4 Troubleshooting 75 Nortel VPN Router Tr oublesho oting Action: V erify that the user name you entere d is correct and retype the password before trying t he connection ag ain.
76 Chapter 4 Troub leshooting NN46110-602 Action: Click Connect to re-establish the extranet connection. If this works, the connection was probably lost due to th e Idle T imeout conf igured on the VPN Router.
Chapter 4 Troubleshooting 77 Nortel VPN Router Tr oublesho oting Action: V a lidate that the VPN Client is conf igured with a DNS entry . For W indo w s NT 4.0, open a command prompt and enter ipconfig/all . V erify that a DNS server entry is listed. For W indow s 95, from the Start menu on the task bar , select Run and enter winipcfg .
78 Chapter 4 Troub leshooting NN46110-602 Cannot access W eb servers on the Internet afte r establishing a VPN Client connection Cause : For both PPTP and IPsec, this condition occurs as a result of all network traf fic passing through the corporate network.
Chapter 4 Troubleshooting 79 Nortel VPN Router Tr oublesho oting Alternati vely , on NT 4.0, W indo ws 98, and W indows 95 , complete the follo wing steps to change your workst ation to be a member of a workgroup instead of a domain: 1 From the Start menu, select Settings > Contr ol P anel .
80 Chapter 4 Troub leshooting NN46110-602 • Start from the top do wn to go in the opposite direction, looking at PPP first and worki ng do wn to the physical connection.
Chapter 4 Troubleshooting 81 Nortel VPN Router Tr oublesho oting Check the HDLC framing Assuming that the T1/V .35 interface is op erati ng correctly , use the follo wing steps to determine whether th.
82 Chapter 4 Troub leshooting NN46110-602 4 If the PPP layer still does not come up, enable the interface deb ugger to generate large amounts of packet tr aces in the e vent log. Report this information to Nortel Customer Support for further diagnosis.
Chapter 4 Troubleshooting 83 Nortel VPN Router Tr oublesho oting • DHCP Server assigns IP addresses to clients • WINS Server provides a translation of the NetBIOS domain name to the IP address •.
84 Chapter 4 Troub leshooting NN46110-602 The client system’ s NetBIOS name must be unique in the priv ate network to which the client is connecting. Do not us e the same name as your of fice d esktop machine or something like my computer . Uniqueness is required.
Chapter 4 Troubleshooting 85 Nortel VPN Router Tr oublesho oting The rene wal interv al gov erns ho w often a c lient must reregister its name with the WINS server . It begins trying at one-half of the rene wal interv al. The extinction interv al gove rns the length of time betwee n when a client name is released and when it becomes extinct.
86 Chapter 4 Troub leshooting NN46110-602 In the WINS mappings entry , enter a show database command. Note the entry for -__MSBR O WSE__. This is the machine that is actually the elected master bro wser , and it changes frequently . If this en try is pointing to an in v a lid machine, it can cause problems.
Chapter 4 Troubleshooting 87 Nortel VPN Router Tr oublesho oting T o specify a computer as the preferred master bro wser, set the parameter for IsDomainMasterBrowser to T rue or Y e s in the following.
88 Chapter 4 Troub leshooting NN46110-602 When 10.1.2.3 broad casts to find a network neighbor , it (incorrec tly) sends to 10.255.255.255. Normal rou ting functionality does not fo rw ard such a packet. The VPN Router finds the best match among its physical interfaces (10.
Chapter 4 Troubleshooting 89 Nortel VPN Router Tr oublesho oting After about 10 to 15 seco nds, NetBIOS g i ves up on the primary interf ace, mov es to the correct tunnel interface, and st arts to bro wse the Network Neighborhood.
90 Chapter 4 Troub leshooting NN46110-602 Y ou must create a connection def inition fo r your initial Internet link through your service provider . A separate connection defin ition is needed for creating the PPTP tunnel.
Chapter 4 Troubleshooting 91 Nortel VPN Router Tr oublesho oting My downloaded DNS server s for m y tunnel connection do not wo r k Cause: The Microsoft Windo ws 95/98 an d W indows NT operating systems attempt to ping ne w DNS servers before addi ng them to the current list of serv ers.
92 Chapter 4 Troub leshooting NN46110-602 • Ho w to T rou bleshoot TCP/IP Connectivity with W indows NT • Remote Access Service (RAS) Error Code List for W indows NT 4.0 • RAS Error 720 When Dialing Out • T roubleshooting PPTP Connecti vity Issues in W indows NT 4.
Chapter 4 Troubleshooting 93 Nortel VPN Router Tr oublesho oting • For Acti veX Scripts, Ja v a, and Jav aSc ript*, you must enable both Acti veX and Jav a programs in Internet Explorer , and enable both Jav a and Jav aScript in Netscape Communicator for prop er VPN Router W eb management windo ws.
94 Chapter 4 Troub leshooting NN46110-602 Clearing y our W eb br ow ser cac he when upgrading T o av oid problems when upgrading soft ware re vision le vels, Nort el recommends that you clear your bro wser cache and exit the bro ws er and all associated windo ws (such as mail and ne ws readers).
Chapter 4 Troubleshooting 95 Nortel VPN Router Tr oublesho oting Document not found messa g e Cause: This message is returned when the HTTP ser ver ca nnot f ind the requested windo w . This can happen be cause the Jav a navigation index f ile is out of sy nch with the rest of the system.
96 Chapter 4 Troub leshooting NN46110-602 Action: Close help windo ws after vie wing them. Distorted backgr ound images Cause: In Nets cape versions prior to 4.0, where you c onfigured your W indows 95, W indo ws 98, or W indows NT system for 8-bit color (256 colors or less), images can ap pear distorte d in the na vigational area.
Chapter 4 Troubleshooting 97 Nortel VPN Router Tr oublesho oting Action: If necessary , remov e the front bezel as described in the installation guide, then push the bottom of the po wer supply in to reseat it.
98 Chapter 4 Troub leshooting NN46110-602 Action: Po wer-c ycle the system using the gr een po wer button on the back of the VPN Router. Solving r outing prob lems The following sections describe ro uting problems . Client address redistrib ution pr oblems The number of current Utunnel host user s can display more than the configur ed maxim um.
Chapter 4 Troubleshooting 99 Nortel VPN Router Tr oublesho oting Solving fire wall pr oblems An error occurred whil e par sing the policy Description: The polic y that you are attempting to view or edit cannot be opened because it does not conform to the required format.
100 Chapter 4 Troubl eshooting NN46110-602 A uthorization failed. Please tr y again. Description: This error occurs when the wron g authentication credentials are entered. The user is re-prompted for creden tials until they are either correct or the user clicks Cancel.
Chapter 4 Troublesho oting 101 Nortel VPN Router Tr oublesho oting Action: T o ensure that the most current data is loaded: 1 Close the current polic y , if opened. Sa ving is not permitted until this error is remedied. 2 From the polic y selection windo w , select All from the Refr esh menu.
102 Chapter 4 Troubl eshooting NN46110-602.
103 Nortel VPN Ro uter Trouble shooting Chapter 5 P acket capture Pack et capture (PCAP) is a troubleshooting tool that network administrators and customer support person nel use, in conjunc tion with other t ools such as statistics, logging, netwo rk analyzers, and testers, to remotely troubleshoot VPN Router and network problems.
104 Cha pter 5 Pack et captur e NN46110-602 PCAP initially occurs to the RAM b u f fer . A low priority task writes the RAM bu ffer to di sk f iles, called the disk capture f iles. Alth ough you can set th e maximum size of this f ile, when the maximum file size is reached, PCAP can continue writing the captured data.
Chapter 5 Packet capt ure 105 Nortel VPN Router Tr oublesho oting • limit the traf fic that t he filters capture • automatically start and stop packet capture wi th triggers Security features Pa cket ca pture on the VPN Router p rovide s the follo wing features to enh ance security: • Pack et capture is disabled by default.
106 Cha pter 5 Pack et captur e NN46110-602 Capture types The VPN Router captures pack ets from the follo wing sources: • Physical interfaces, includi ng the following: — Asynchronous digital subs.
Chapter 5 Packet capt ure 107 Nortel VPN Router Tr oublesho oting T unnel ca ptures sav ed to disk are encap sulated with raw IP encapsulation. When you con vert these f iles to file formats th at do not support ra w IP encapsulation (including Snif fer), L2 encapsulation is required.
108 Cha pter 5 Pack et captur e NN46110-602 A global IP capture object captures pa ckets beginning from the IP header; no Layer 2 header is sav ed in the capture f ile. Because both encrypted and decrypted packets are captured, global IP pack et capture is useful in trou bleshooting certain VPN issues.
Chapter 5 Packet capt ure 109 Nortel VPN Router Tr oublesho oting •A start trigg er causes the sy stem to w ait for a spec if ic pack et before it st arts saving pack ets to the capture bu f fer .
110 Cha pter 5 Pack et captur e NN46110-602 Y ou can create ne w capture objects un til the maximum block size reaches 25 Mbyte. (The VPN Router do es not allo w you to reduce the maximum block size to less than 25 Mbyt e.
Chapter 5 Packet capt ure 111 Nortel VPN Router Tr oublesho oting • Delete a capture object or capture files when you n o longer need them to free up memory or disk space. • Do not run capture objects for physical interfaces or tunnels at the sa me time that you run th e global IP capture object (some p ackets are captured more than once).
112 Cha pter 5 Pack et captur e NN46110-602 6 Enter the administrator’ s user name and passw ord. Please enter the administrat or's user name: admin Please enter the administrat or's password: ***** The serial main menu appears. Main Menu: System is currently in NORMAL mode.
Chapter 5 Packet capt ure 113 Nortel VPN Router Tr oublesho oting 10 If you want, you can now change the VPN Router administrator p assword. CES# configure terminal Enter configuration commands , one per line.
114 Cha pter 5 Pack et captur e NN46110-602 Fo r example , enter: CES(capture-ethernet) #filepath /ideX/ system/log Setting the size of the RAM buff er T o set the RAM buf fer size, from CLI Capture Conf iguration Mode enter: buffersize < size > where size is the size of the RAM buf fer .
Chapter 5 Packet capt ure 115 Nortel VPN Router Tr oublesho oting Fo r example , enter: CES(capture-ethernet) #maxfiles 99 Saving captured data T o set the PCAP capture mode to loss or no loss, from C.
116 Cha pter 5 Pack et captur e NN46110-602 For e xample, enter the following command: CES# capture add test1 ? atm ATM interfac e capture bri Bri interf ace capture dial Dial inter face capture FastE.
Chapter 5 Packet capt ure 117 Nortel VPN Router Tr oublesho oting T o conf igure a capture object: 1 Navigate to Captur e Configurati on m o d e b y e n t e r i n g t h e capture command with the object name.
118 Cha pter 5 Pack et captur e NN46110-602 T unnel capture parameters Capture objects for tunnels ha ve se ve ral unique parameters. The follo wing example creates a tunnel object called bot1 , na vigates to Capture Conf iguration mode, and displays the co mmands for tunnel obje cts.
Chapter 5 Packet capt ure 119 Nortel VPN Router Tr oublesho oting Global IP parameters The conf igurable parameters for the global IP capture object are the same as the parameters av ailable for physical interf ace objects.
120 Cha pter 5 Pack et captur e NN46110-602 In the follo wing example, the sho w capture command is run with no object name to display a list of all the captu re objects configured on the VPN Router.
Chapter 5 Packet capt ure 121 Nortel VPN Router Tr oublesho oting Sample pac ket captu re configurations This section provides sample conf igura tions and the commands us ed to create them.
122 Cha pter 5 Pack et captur e NN46110-602 T o vie w the status of the runni ng capture object, as well as its conf iguration, use the show capture command.
Chapter 5 Packet capt ure 123 Nortel VPN Router Tr oublesho oting T o create and use this capture object, you run commands like the ones i llustrated in this example. These commands do the follo wing: 1 Create a capture object called test-trigger on Fast Ether net interface 0/1 .
124 Cha pter 5 Pack et captur e NN46110-602 After T elnet traff ic activ ates the stop trigger , the show capture command resembles the follo wing example.
Chapter 5 Packet capt ure 125 Nortel VPN Router Tr oublesho oting 4 Exit Captur e Conf iguration mode. 5 Start the capture. CES# capture add test-remote-ip tunnel CES# capture test-remote-ip CES(capture-tunnel)# remoteip 192.
126 Cha pter 5 Pack et captur e NN46110-602 3 Click ether eal-setup- n.nn.n .exe . 4 Click a do wnload site and save the ex ecutable file on your hard dri ve. 5 Double-click the ex ecutable file to install Eth ere al software in the c:Pro gram FilesEthereal directory .
Chapter 5 Packet capt ure 127 Nortel VPN Router Tr oublesho oting 6 Enter the password that you entered wh en you enabled packet capture (see “Enabling packet capture on a VPN Router” on page 111 ). 7 From the open Ethereal window , disable Enable network name r esolution .
128 Cha pter 5 Pack et captur e NN46110-602 T1 frame relay capture: editcap -F ngsniffer d:pcapfr.cap frelay.syc 5 From Sniffer Pr o , open the .enc file or the .syc file to vie w the trace. For a global IP trace or tunnel trace, you must perform an extra step on Snif fer Pro because only Layer 3 traf f i c is recorded in the PCAP capture.
Chapter 5 Packet capt ure 129 Nortel VPN Router Tr oublesho oting T o delete a pack et capture object: 1 Display all conf igured capture objects on the VPN Router to locate the object or objects that you w ant to delete.
130 Cha pter 5 Pack et captur e NN46110-602.
131 Nortel VPN Ro uter Trouble shooting Appendix A MIB suppor t The VPN Router supports the management information base (MIB) for use with network mana gement protocols in TCP/IP-based Intern ets and TCP/IPX-based networks. T he VPN Router supports SNMP Gets only .
132 Appendix A MIB support NN46110-602 RFC 1724—RIP V ersion 2 MIB Extension The VPN Router supports RFC 1724, R IP V ersion 2 MIB Extension . As stated in the introduction to the RFC, the RFC “d efines a portion of the Management Information Base (MIB) for use with netw ork management protocols in TCP/ IP-based internets.
Appendix A MIB support 13 3 Nortel VPN Router Tr oublesho oting RFC 2787—VRRP MIB The VPN Router supports RFC 2787, Def initions of Manag ed Objects for the V irtual Router Redundancy Pr otocol . As stated in the introduction, RFC 2787 “def ines an extension to th e Management Information Base (MIB) for use with SNMP-based netw ork management.
134 Appendix A MIB support NN46110-602 RFC 1573—IanaIfT ype MIB This MIB contains the enumerations for rfc2233 ifT able.ifT ype. These enumerations describe the v arious types of interfaces that ifT able can support. RFC 2233—If MIB This MIB is the latest e volution of rfc12 13 Interf aces group, plus se veral ne w objects.
Appendix A MIB support 13 5 Nortel VPN Router Tr oublesho oting — hrNetworkT able — hrPrinterT able — hrDiskStorageT able hrDiskStorageCapacity — hrPartit ionT able hrPartitionSize — hrFST a.
136 Appendix A MIB support NN46110-602 RFC2863 Interface MIB ( 64 bit counter s suppor t) The support for the following entries w as a dded in the interface table: ifHCInOctets, ifHCInUcastPkts, ifHCOu tOctets and ifHCOutUcastPkts. These counters already existed and were ex tended from Coun ter32 to Counter64.
Appendix A MIB support 13 7 Nortel VPN Router Tr oublesho oting cestraps.mib—Nor tel pr oprietary MIB This section lists the cont ents of the cestraps.
138 Appendix A MIB support NN46110-602 -- The second means packets were dropp ed due to a detected spoofed address -- The third should never happen, but means the status has been set to a bogus value.
Appendix A MIB support 13 9 Nortel VPN Router Tr oublesho oting ne w o ak.mib This section provides the contents of the ne woak.mib, which def ines the newoak enterprise ID, the contivity object identif ier , and the sysObjectIDs for ea ch VPN Router model.
140 Appendix A MIB support NN46110-602 Har dware-related traps hardwareTrapInfo OBJECT IDEN TIFIER ::= {ContivitySnmpTraps 1} -- Trap #1001 hardDisk1Status OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Hard Disk Numbe r 1 Status.
Appendix A MIB support 14 1 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "Status of the f irst CPU fan." ::= {hardwareTrapInfo 6} -- Trap #1007 fanTwoStatus OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of the s econd CPU fan.
142 Appendix A MIB support NN46110-602 ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.5VA power." ::= {hardwareTrapInfo 12} -- Trap #10013 twoDotFiveVB OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.
Appendix A MIB support 14 3 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "The chassis int rusion sensor indicates that the unit has been opened.
144 Appendix A MIB support NN46110-602 Server-related traps serverTrapInfo OBJECT IDENTI FIER ::= {ContivitySnmpTraps 2} -- Trap #3001 radiusAcctServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of Exter nal Radius Accounting Server.
Appendix A MIB support 14 5 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "Status of DNS Server." ::= {serverTrapInfo 6} -- Trap #3007 SNMPServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of SNMP Server.
146 Appendix A MIB support NN46110-602 Software-related traps softwareTrapInfo OBJECT IDEN TIFIER ::= {ContivitySnmpTraps 3} -- Trap #5001 NetBuffers OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Network buffer usage.
Appendix A MIB support 14 7 Nortel VPN Router Tr oublesho oting Intrusion-related traps intrusionTrapInfo OBJECT IDE NTIFIER ::= {ContivitySnmpTraps 5} -- Trap #201 securityIntrusion OBJECT-TYP E SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Login Security Intrusion.
148 Appendix A MIB support NN46110-602 Inf o rmation passed with e very trap SeverityLevel OBJECT-TYPE SYNTAX INTEGER { fatal(1), major(2), minor(3), informational(4), insignificant(5), reversal(6) } ACCESS read-only STATUS mandatory DESCRIPTION "Severity of spe cific trap.
Appendix A MIB support 14 9 Nortel VPN Router Tr oublesho oting Ta b l e 3 provides trap categori es and explanations. T able 3 T rap categ ories Hard ware 1.3.6.1.4.1.2505.1.1.0.1001 hardDisk 1StatusTrap 1.3.6.1.4.1.2505.1.1.0.1002 hardDisk 0StatusTrap 1.
150 Appendix A MIB support NN46110-602 Ta b l e 4 provides descriptions for the VPN Router traps. Server 1.3.6.1.4.1.2505.1.2.0.3007 snmpServ erTrap 1.3.6.1.4.1.2505.1.2.0.3008 ipAddres sPoolTrap 1.3.6.1.4.1.2505.1.2.0.3009 extLDAPS erverTrap 1.3.6.1.
Appendix A MIB support 15 1 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.1009 f iv eV olts P osStatu sT rap Status of the +5 V ol t power . Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10010 five V oltsMinusT rap Status of -5 V olt pow er .
152 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10020 t1 W ANStatusT rap St atus of T1 W AN card(s); P ossible v a lues f or W anic: Aler t: Inv alid Device X. W ar ning: Device W anicX disab led. Aler t: Device W anicX down.
Appendix A MIB support 15 3 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10022 hw AccelT rap Status of hardware accelerator card. P ossible V alues: Inv alid hardware accelerator unit %d. Unknown hardware accelerator unit %d.
154 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10024 v90W AN StatusT rap Status of V .90 Interface card. P ossible V alues: Please note that X corresponds to the unit number of the card. Aler t: V .90 Inv alid index X. Disabled: De vice IntModem-X disabled.
Appendix A MIB support 15 5 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10026 serUar tStatusT rap Status of Serial (COM) por t/ interface . P ossible V alues: Please note that X corresponds to the unit number of the serial interface .
156 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.2.0.3005 loadBala nci ngSer verT rap Status of Load Balancing Ser v er . Proprieta r y 1.3.6.1.4.1.2505.1.2.0.3006 dnsSer ve rT rap Status of DNS Server . Proprieta r y 1.3.6.1.4.
Appendix A MIB support 15 7 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.2.0.30014 dhcpSer verT rap Status of DHCP Ser ver . P ossible V alues: Disabled: DHCP Server is Disabled. Aler t: DHCP Ser v er is NO T configured. Aler t: DHCP Ser v er is configured and operational, Usi ng backup config.
158 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.3.0.5007 sslV pnStatusT rap Status of SSL-VPN Accelerator . P ossible V alu es: Disabled: Disabled—The unit is administratively disab led. Disabled: HW not installed— There is no SSL-VPN Accelerator installed.
Appendix A MIB support 15 9 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending proto col entity recogni zes a f ailure in one of the communication links represen ted in the agent's configuration.
160 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending proto col entity recogni zes that one of the communicati on links represented in the agent's configuration is up . V arbind list: ifInde x—ifInde x of the interface .
Appendix A MIB support 16 1 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure n aut henticationF ailure trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message that is not properly au thenticated.
162 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending proto col entity recogni zes a f ailure in one of the communication links represen ted in the agent's configuration. V arbind list: ifInde x—ifInde x of the interface .
Appendix A MIB support 16 3 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending proto col entity recogni zes that one of the communicati on links represented in the agent's configuration is up .
164 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure An aut henticationF ailu re trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message that is not properly au thenticated. The snmpEnableA uthenT raps object indicates whether this trap is generated.
165 Nortel VPN Ro uter Trouble shooting Appendix B Using serial PPP Y ou use Serial Point-to-Poin t Protocol (PPP) to manage the VPN Router from a remote location using PPP and the serial interface. If the VPN Router becomes unreachable ov er the Internet, you can s till dial up and mana ge it through the serial interface menu.
166 Appendix B Using serial PPP NN46110-602 Setting up a Dial-Up Netw orking connection T o establish a Serial PPP connection us ing a Microsoft Dial-Up Netw orking connection from the client system: 1 Double-click My Computer . 2 Double-click the Microsoft Di al-Up Networking icon .
Appendix B Using serial PPP 167 Nortel VPN Router Tr oublesho oting Setting up the modem The follo wing procedure assumes that you are using a 3Com/US Robotics 5 6K x2 modem. It describes how to set up a modem to co mmunicate with the VPN Router using a dial-up network ing connection.
168 Appendix B Using serial PPP NN46110-602 to access all management services (HTTP , T elnet, FTP , SNMP) through the W eb interface. Once you establis h a session through PPP , the serial interface acts as a pri vate W AN interface with an internal IP address (0.
Appendix B Using serial PPP 169 Nortel VPN Router Tr oublesho oting Dialing in to the VPN Router Use the standard dial-up networking pr ocedure to connect to the VPN Router. After connecting, you can then manage th e VPN Router using either T elnet (for the command line interface) or the browser -based G UI.
170 Appendix B Using serial PPP NN46110-602 Cause: Y ou were dialed in and managing the VPN Router remotely using PPP and you changed the baud rate and applied it, bu t no w you cannot manage the VPN Router. Action: T o manage the VPN Router, disconnect the dial-up connection and try to re-establish it.
Appendix B Using serial PPP 171 Nortel VPN Router Tr oublesho oting Action: Make sure that the modem that is connec ted to the VPN Router has hardware flo w control enable d. PPP option settings The follo wing settings describe the VP N Router’ s behavior when ne gotiating serial PPP .
172 Appendix B Using serial PPP NN46110-602.
173 Nortel VPN Ro uter Trouble shooting Appendix C System messages System forwarding (syslog) uses the syst em logging daemon (syslogd) to forw ard information from the VPN Router system log to dif ferent host machines. This appendix provides a listing of possib le syslog messages that the VPN Router can write to a remote system.
174 Appendix C System messages NN46110-602 tCer t: Shutdown complete Description: This informational message indica tes that the task responsible for certificate maintenance is shut do wn. This is usually part of the normal system shutdo wn. Action: No action required.
Appendix C System messages 175 Nortel VPN Router Tr oublesho oting 2 Manually verify the tunnel-related ce rtif icate fingerprints. Perform this procedure any time you suspect tamp ering. ISAKMP messages ISAKMP [ 13 ] No pr oposal chosen in message from xxx (a.
176 Appendix C System messages NN46110-602 Action: Make sure the PFS settings on both sides match. Either enable PFS on the remote side, or disable PFS locally . ISAKMP [ 13 ] Err or notification (No pr oposal chosen) received from xxx (a.b.c.d) Description: The proposal made by the local VPN Router is reject ed by a VPN Client.
Appendix C System messages 177 Nortel VPN Router Tr oublesho oting ISAKMP [ 13 ] Error notification (A uthent ication failure) received from xxx (a.b.c.d) Description: A VPN Client attempted to connect , b ut the user supplied the wrong password. Action: Make sure that the user and the VPN Router ha ve the same password.
178 Appendix C System messages NN46110-602 ISAKMP [ 13 ] In v alid ID informat ion in message fr om xxx (a.b.c.d) Description: One side of the connection is conf igured to support dynamic routing while the other side is con figured for static routing.
Appendix C System messages 179 Nortel VPN Router Tr oublesho oting Action: Remov e the existing static route or change the route for the remote network to be a sub set or superset of the static route. SSL messages Checking c hain: in valid parent cert, xxx Description: The gi ven certif icate in the chain is not v alid.
180 Appendix C System messages NN46110-602 No matching trusted CA certs Description: None of the certificates in the ch ain are truste d CA certificates. Y ou can recei ve this message if the CA certif ic at e is not installed or is not marked as trusted on the VPN Router.
Appendix C System messages 181 Nortel VPN Router Tr oublesho oting Action: Make sure the b ackup f ile has an 8.3 f ile name. LDIF file: could not restore xxx Description: The internal LD A P server database cannot be restored from the specif ied LDIF file.
182 Appendix C System messages NN46110-602 CaA uthSer verCollection: authenticate xxx cer t [xxx] in valid signature b y [xxx] - xxx Description: The certif icate passed in with th e authentication request does not ha ve a v alid signature, based on the CA certificate conf igured on the VPN Router.
Appendix C System messages 183 Nortel VPN Router Tr oublesho oting Action: Start the LD AP se rver , or change the external LD AP server conf iguration to make it accessible. Security: store ne w system subnet mask xxx failed— xxx Description: The system subnet mask cannot be stored in the VPN Router conf iguration LD AP entry .
184 Appendix C System messages NN46110-602 Action: Start the LD AP se rver , or change the external LD AP server conf iguration to make it accessible. Err or deleting entry [xxx]—xxx Description: An er ror occurred while deleting an LD AP entry . This indicates that the LD AP server is not accessible.
Appendix C System messages 185 Nortel VPN Router Tr oublesho oting xxx xxx being referenced b y xxx Description: The LD AP entry is referenced by another LD AP entry (for example, a f ilter set referenced b y a User Group or Branch Of fice Connection).
186 Appendix C System messages NN46110-602 Session: xxx[xxx]:xxx xxx auth method not allowed Description: The authentication method of the in coming request is not allo wed in the group that th e session is bound to .
Appendix C System messages 187 Nortel VPN Router Tr oublesho oting Session: xxx[xxx] : xxx IP address assignment failed Description: An address cannot be assigned to the session. This occurs if the static address for the session is in use or if the address po ol is exh austed.
188 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx account not allowed now Description: The session request is outside the permitted hours of access. Action: Change the Access Hours setting assigned to the group on the Profiles > Groups > Edit > Connecti vity window .
Appendix C System messages 189 Nortel VPN Router Tr oublesho oting Session: xxx[xxx] : xxx in valid pass w ord —master admin authentication failed Description: The primary administrator passw o rd is in valid. This results from using the wrong passw ord or from making a mistake while ty ping the password.
190 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx pool address [xxx] already in use Description: The returned static pool address is currently is use. This error occurs if another tunnel is using this address through a static address conf iguration or another address pool.
Appendix C System messages 191 Nortel VPN Router Tr oublesho oting RADIUS accounting messages RADIUS: Cannot send ac counting request to < ser ver-name >, possibl y due to DNS translation failure Description: This message indicates a conn ection failure.
192 Appendix C System messages NN46110-602 RADIUS: network soc ket failure with < ser ver-name >, recvfr om err or: < err or > Description: This message indicates a connection failure. An error occurred while receiving the response. Action: Retry authentic ation attempt and v erify that RADIUS serv er packets are properly formed.
Appendix C System messages 193 Nortel VPN Router Tr oublesho oting Action: Retry authentic ation attempt and v erify that RADIUS serv er packets are properly formed. Unsuppor ted response type (< numb e r >) received from server Description: This message indicates that an in v alid response was recei ved.
194 Appendix C System messages NN46110-602 RADIUS authentication messages RADIUS: Cannot sen d request to < ser ver-name >, possib ly due to DNS translation failure Description: This message indicates a conn ection failure. Whi le sending a request, an error occurred du e to a socket creation probl em.
Appendix C System messages 195 Nortel VPN Router Tr oublesho oting RADIUS: < server-name > server timed out authenticating < user-name > Description: This message indicates a connec tion failure. The connection timed out while waiting for a response.
196 Appendix C System messages NN46110-602 RADIUS: < server-name > sent in v alid response packet f or < user-name > Description: This message indicates that an in v alid response was recei ved. The length of the response packet is not equal to the number of bytes recei ved.
Appendix C System messages 197 Nortel VPN Router Tr oublesho oting Action: V erify that the shared secrets match. RADIUS: < server-name > sent pac ket with in valid response authenticator f or < user -name > Description: This message indicates that an in v alid response was recei ved.
198 Appendix C System messages NN46110-602 RADIUS: < user-name > access DENIED b y ser ver < server-name > Description: This message indicates that a v a lid access-reject response was recei ved. Action: No action required. Response OK Description: This message indicates that a valid access-accept response was recei ved.
Appendix C System messages 199 Nortel VPN Router Tr oublesho oting Action: No action required. Closing OSPF-RTM connection Description: OSPF closed the R TM connection, wh ich occurs if the administrator disables OSPF from Routing > OSPF window . Action: No action required.
200 Appendix C System messages NN46110-602 Can not accept x.x. x.x as router id Description: OSPF can not accept the gi ven router ID in the Routing > OSPF windo w . Action: Y ou must chan ge router ID in the Routing > OSPF window . In va lid router IDs are 127.
Appendix C System messages 201 Nortel VPN Router Tr oublesho oting VR xxx : Star ting xxx as Bac kup for xxx Description: Logged when starting as a backup for an address. The parameters are: • The VRID of this VR • The reason for starting, either because it was enabled or the interface went up • The IP addre ss Action: No action required.
202 Appendix C System messages NN46110-602 Unable to get conf iguration for VR xxx Description: This is an error e vent that is lo gged when VRRP is enabled bu t the common configuration parameters are mi ssing. These are the items set in the Routing > VRRP windo w .
Appendix C System messages 203 Nortel VPN Router Tr oublesho oting RIP xxx : Circuit xxx deleted Description: Logged when the RIP circuit is de leted. The parameter stands for circuit ID. Action: No action required. RIP xxx : Unable to register with UDP Description: Logged when you can not re gister with UDP protocol.
204 Appendix C System messages NN46110-602 RIP xxx : Unable to spa wn timer task xxx fo r R I P Description: Logged when RIP fails to spaw n the timer task.
Appendix C System messages 205 Nortel VPN Router Tr oublesho oting Interface [ nnn ] replaced, deleting fr om config Description: This indicates the card type specif ied in the configurat ion file does not match the card currently in the sl ot. The interface is deleted from the conf iguration.
206 Appendix C System messages NN46110-602.
207 Nortel VPN Ro uter Trouble shooting Appendix D Configuring f or interoperability This chapter e xplains the requirements and p rocedures for setting up dif ferent vendor hardw are or software to intero perate with the VPN Router. Y ou can use these instructions to establish encrypted tunnels to and from the VPN Router with the noted v endors.
208 Appendix D Config uring for in teroperability NN46110-602 Figure 11 VPN Router and Cisco 2514 netw or k topolog y.
Appendix D Configurin g for interoperability 209 Nortel VPN Router Tr oublesho oting The follo wing is a show config command: Cisco2514# show config Using 1088 out of 32762 byte s version 11.3 no service password-encryption hostname Cisco2514 enable secret 5 $1$aSJB$Xz/o 4I4IqCY.
210 Appendix D Config uring for in teroperability NN46110-602 dialer-list 1 protocol ipx p ermit snmp-server community public RO line con 0 line aux 0 line vty 0 4 password terminal login end Configur.
Appendix D Configurin g for interoperability 211 Nortel VPN Router Tr oublesho oting Configuring the SafeNet/Soft-PK Security P olicy Database Editor , V er sion 1.
212 Appendix D Config uring for in teroperability NN46110-602 Connecting to IRE SafeNET/So ft-PK Security P olicy Client T o set up the VPN Router to establish encrypted tunnel connections with the IRE SafeNet/Soft-PK Security Polic y Client, do the follo wing: 1 Open the SafeNet/Soft-PK Secu rity Polic y Client, and click File: New .
Appendix D Configurin g for interoperability 213 Nortel VPN Router Tr oublesho oting • 8.1.10.42 The SafeNet/Soft PX Security Po lic y Editor dialog box appears. 6 Click My Identity to conf igure the SafeNet clie nt, and select the following: • Select Certificate: None •I D T y p e : IP Address • Port: All 7 Click Pr e-Shared K ey .
214 Appendix D Config uring for in teroperability NN46110-602 The SafeNet/Soft-PK Security Po lic y Editor dialog box appears. 10 From Security Policy: Select Phase 1 Negotiation Mode , click Main Mode .
Appendix D Configurin g for interoperability 215 Nortel VPN Router Tr oublesho oting • Authentication Method: Pr e-Shar ed key • Encrypt Alg: DES •H a s h A l g : MD5 •S A L i f e : Seconds an.
216 Appendix D Config uring for in teroperability NN46110-602 9 For some v e ndors, if you want to turn off V endor ID and/or P erfect F orward Secrecy (PFS) , do that on the Prof iles > Groups > IPsec: Conf igure windo w .
Appendix D Configurin g for interoperability 217 Nortel VPN Router Tr oublesho oting Considerations f or usin g third- par ty c lients There are sev eral considerations regarding the use of third-part.
218 Appendix D Config uring for in teroperability NN46110-602 • Load Balancing—T raditional load balancers often do not work with the IPsec protocol because of the security featur es on individual packets and separate ke y management and data channels.
Appendix D Configurin g for interoperability 219 Nortel VPN Router Tr oublesho oting (are correctly decrypted, and authenti cated) are accepted; other packets are dropped. If an y attempt is made to chan ge the station address of the client, the tunnel is automatically closed.
220 Appendix D Config uring for in teroperability NN46110-602 then select a default server certif icate from the list. Y ou configure servers from the System > Certif icates windo w . 7 Select Prof iles > Branch Off ice , click Edit , scroll do wn to the IPsec section and click Conf igure .
Appendix D Configurin g for interoperability 221 Nortel VPN Router Tr oublesho oting Figure 13 Split tunneling e xample T o configure the VPN Router as a user tunnel: 1 Select Prof iles > Gr oups and click Add . Enter a group name of up to 64 characters (spaces are pe rmitted); for example, Research and De velopment.
222 Appendix D Config uring for in teroperability NN46110-602 6 Selections in the Encryption field s are dependent on the type of encryption that your third-p arty client supports. 7 Enable Perfect F orw ard Secrecy (PFS) . PFS ensures that if one ke y is compromised, subsequent ke ys are not compromised.
Appendix D Configurin g for interoperability 223 Nortel VPN Router Tr oublesho oting Network addresses fo rm the basis of the IPX internetwork addressing scheme for sending packets between netw ork segm ents.
224 Appendix D Config uring for in teroperability NN46110-602 Windows 95 and Windo ws 98 When running W indows 95 or W i ndows 98, load the intraNetW are* client, which is a v ailable from the No vell W eb site: http://www.
Appendix D Configurin g for interoperability 225 Nortel VPN Router Tr oublesho oting Figure 14 IPX topolog y Note: The pri v ate LAN can also carry IP and IPX traf fic simultaneously .
226 Appendix D Config uring for in teroperability NN46110-602.
Nortel VPN Ro uter Trouble shooting 227 Inde x A accounting data 40 records 38, 39 accounting log 38 acti ve sessions 96 Acti veX Scripts 93 administrato r settings 28 administrator privileges 27 auth.
228 Ind ex NN46110-602 SSL 179 e v ent log 35, 41 External DHCP server 97 extinction interval 84 timeout 84 Extranet Access client monitor 70 connection problems 73 F factory default 49 configuration .
Index 229 Nortel VPN Router Tr oublesho oting modem hardware errors 82 MS-DOS naming con vention 97 multiple Help windows 95 N NetBEUI 77, 83 NetBIOS 77, 83, 84, 88 Netscape Communicator 92 netstats command 71 NetW are client 224 Network Neighborhood 84 ne woak.
230 Ind ex NN46110-602 RADIUS accounting 191 RADIUS authentication 194 routing 198 security 181 SSL 179 T T1/V .35 interface 80 technical publications 22 text con ventions 17 tools ARP 30 ping 29 trac.
An important point after buying a device Nortel NN46110-602 (or even before the purchase) is to read its user manual. We should do this for several simple reasons:
If you have not bought Nortel NN46110-602 yet, this is a good time to familiarize yourself with the basic data on the product. First of all view first pages of the manual, you can find above. You should find there the most important technical data Nortel NN46110-602 - thus you can check whether the hardware meets your expectations. When delving into next pages of the user manual, Nortel NN46110-602 you will learn all the available features of the product, as well as information on its operation. The information that you get Nortel NN46110-602 will certainly help you make a decision on the purchase.
If you already are a holder of Nortel NN46110-602, but have not read the manual yet, you should do it for the reasons described above. You will learn then if you properly used the available features, and whether you have not made any mistakes, which can shorten the lifetime Nortel NN46110-602.
However, one of the most important roles played by the user manual is to help in solving problems with Nortel NN46110-602. Almost always you will find there Troubleshooting, which are the most frequently occurring failures and malfunctions of the device Nortel NN46110-602 along with tips on how to solve them. Even if you fail to solve the problem, the manual will show you a further procedure – contact to the customer service center or the nearest service center