EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 04:16:09.183 07/10/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 04:16:09.193 07/10/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 3 04:16:09.193 07/10/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 4 04:16:09.233 07/10/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 3955 for TCP connection. 5 04:16:09.493 07/10/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 6 04:16:09.493 07/10/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 7 04:16:09.493 07/10/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 3955, dst port 4005 8 04:16:09.493 07/10/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 3955 9 04:16:09.493 07/10/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 3955, dst port 4005 10 04:16:09.493 07/10/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 11 04:16:10.004 07/10/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 12 04:16:10.004 07/10/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 13 04:16:10.014 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 14 04:16:10.184 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 15 04:16:10.184 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 16 04:16:10.184 07/10/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 17 04:16:10.184 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 18 04:16:10.184 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 19 04:16:10.184 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 20 04:16:10.214 07/10/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 21 04:16:10.224 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 22 04:16:10.224 07/10/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 23 04:16:10.224 07/10/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 24 04:16:10.244 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 25 04:16:10.244 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 26 04:16:10.244 07/10/06 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.16" from primary server 27 04:16:10.244 07/10/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=D1A4926863CF4215 R_Cookie=8615BE6B020C608D) reason = DEL_REASON_LOAD_BALANCING 28 04:16:10.244 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 29 04:16:10.996 07/10/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=D1A4926863CF4215 R_Cookie=8615BE6B020C608D) reason = DEL_REASON_LOAD_BALANCING 30 04:16:10.996 07/10/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 31 04:16:10.996 07/10/06 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.16" given by the primary server 32 04:16:10.996 07/10/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 33 04:16:10.996 07/10/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 34 04:16:11.496 07/10/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 3955, dst port 4005 35 04:16:11.496 07/10/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.16, src port 3955, dst port 4005 36 04:16:11.496 07/10/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.16, src port 4005, dst port 3955 37 04:16:11.496 07/10/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.16, src port 3955, dst port 4005 38 04:16:11.496 07/10/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.16" 39 04:16:11.997 07/10/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 40 04:16:12.007 07/10/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.16. 41 04:16:12.017 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.16 42 04:16:12.177 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 43 04:16:12.177 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.16 44 04:16:12.177 07/10/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 45 04:16:12.177 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 46 04:16:12.177 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 47 04:16:12.177 07/10/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 48 04:16:12.187 07/10/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 49 04:16:12.187 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.16 50 04:16:12.187 07/10/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 51 04:16:12.187 07/10/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 52 04:16:12.217 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 53 04:16:12.217 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 54 04:16:12.217 07/10/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 55 04:16:25.456 07/10/06 Sev=Info/4 CM/0x63100017 xAuth application returned 56 04:16:25.456 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 57 04:16:28.360 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 58 04:16:28.360 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 59 04:16:28.360 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 60 04:16:28.360 07/10/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 61 04:16:28.430 07/10/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 62 04:16:28.430 07/10/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 63 04:16:28.430 07/10/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 64 04:16:28.430 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 65 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 66 04:16:29.392 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 67 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.13.6.71 68 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.192.0 69 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 137.69.224.15 70 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.221.12.10 71 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 72 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 73 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas West Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 74 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 75 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 76 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 77 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 78 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_INCLUDE_LOCAL_LAN (# of local_nets), value = 0x00000001 79 04:16:29.392 07/10/06 Sev=Info/5 IKE/0x6300000F LOCAL_NET #1 subnet = 192.168.1.0 mask = 255.255.255.0 protocol = 0 src port = 0 dest port=0 80 04:16:29.392 07/10/06 Sev=Info/4 CM/0x63100019 Mode Config data received 81 04:16:29.402 07/10/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.13.6.71, GW IP = 137.69.115.16, Remote IP = 0.0.0.0 82 04:16:29.402 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 137.69.115.16 83 04:16:29.402 07/10/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 84 04:16:29.402 07/10/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 85 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 86 04:16:29.432 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.16 87 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 88 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 17 seconds, setting expiry to 86383 seconds from now 89 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 90 04:16:29.432 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.16 91 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 92 04:16:29.432 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 137.69.115.16 93 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=6E1086D7 OUTBOUND SPI = 0x28924D4E INBOUND SPI = 0xCF069400) 94 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x28924D4E 95 04:16:29.432 07/10/06 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0xCF069400 96 04:16:32.826 07/10/06 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.13.6.71/255.255.192.0 DNS=137.69.224.15,128.221.12.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 97 04:16:32.836 07/10/06 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 98 04:16:32.856 07/10/06 Sev=Info/4 CM/0x6310001A One secure connection established 99 04:16:32.866 07/10/06 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.2. Current address(es): 192.168.1.2, 10.13.6.71. 100 04:16:32.866 07/10/06 Sev=Info/4 CM/0x63100038 Address watch added for 10.13.6.71. Current address(es): 192.168.1.2, 10.13.6.71. 101 04:16:33.316 07/10/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 102 04:16:33.316 07/10/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x4e4d9228 into key list 103 04:16:33.316 07/10/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 104 04:16:33.316 07/10/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x009406cf into key list 105 04:16:33.316 07/10/06 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.13.6.71 106 04:16:44.543 07/10/06 Sev=Info/4 IPSEC/0x63700019 Activate outbound key with SPI=0x4e4d9228 for inbound key with SPI=0x009406cf 107 04:21:12.469 07/10/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 3955, dst port 4005 108 04:26:13.044 07/10/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 3955, dst port 4005 109 04:27:29.153 07/10/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 1754095523 110 04:27:29.153 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 111 04:27:29.183 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 112 04:27:29.183 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.16 113 04:27:29.183 07/10/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.16, seq# received = 1754095524, seq# expected = 1754095524 114 04:31:13.473 07/10/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 3955, dst port 4005 115 04:35:56.938 07/10/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 1754095524 116 04:35:56.938 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 117 04:35:56.968 07/10/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 118 04:35:56.968 07/10/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.16 119 04:35:56.968 07/10/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.16, seq# received = 1754095525, seq# expected = 1754095525 120 04:36:13.461 07/10/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 3955, dst port 4005 121 04:41:14.401 07/10/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 3955, dst port 4005 122 04:41:21.421 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 137.69.115.16 123 04:41:21.421 07/10/06 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 28924D4E INBOUND SPI = CF069400) 124 04:41:21.421 07/10/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=6E1086D7 125 04:41:21.421 07/10/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=C61F6D332ED01A26 R_Cookie=B174A0E04328B16A) reason = DEL_REASON_RESET_SADB 126 04:41:21.421 07/10/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.16 127 04:41:21.421 07/10/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=C61F6D332ED01A26 R_Cookie=B174A0E04328B16A) reason = DEL_REASON_RESET_SADB 128 04:41:21.421 07/10/06 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_RESET_SADB. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 129 04:41:21.421 07/10/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 130 04:41:21.421 07/10/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 131 04:41:21.421 07/10/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 3955 for TCP connection. 132 04:41:21.421 07/10/06 Sev=Info/6 CM/0x63100031 Tunnel to headend device 137.69.115.16 disconnected: duration: 0 days 0:24:49 133 04:41:21.481 07/10/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 134 04:41:21.491 07/10/06 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter