EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 00:23:43.421 08/21/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 00:23:43.461 08/21/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 3 00:23:43.461 08/21/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 4 00:23:43.481 08/21/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 1145 for TCP connection. 5 00:23:43.631 08/21/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 6 00:23:43.631 08/21/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 7 00:23:43.631 08/21/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 1145, dst port 4005 8 00:23:43.631 08/21/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 1145 9 00:23:43.631 08/21/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 1145, dst port 4005 10 00:23:43.631 08/21/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 11 00:23:44.132 08/21/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 12 00:23:44.152 08/21/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 13 00:23:44.172 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 14 00:23:44.352 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 15 00:23:44.352 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 16 00:23:44.352 08/21/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 17 00:23:44.352 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 18 00:23:44.352 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 19 00:23:44.352 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 20 00:23:44.392 08/21/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 21 00:23:44.392 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 22 00:23:44.392 08/21/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 23 00:23:44.392 08/21/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 24 00:23:44.422 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 25 00:23:44.422 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 26 00:23:44.422 08/21/06 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.16" from primary server 27 00:23:44.422 08/21/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=DAD880460C03DF1D R_Cookie=662D44542AB75612) reason = DEL_REASON_LOAD_BALANCING 28 00:23:44.422 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 29 00:23:45.134 08/21/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=DAD880460C03DF1D R_Cookie=662D44542AB75612) reason = DEL_REASON_LOAD_BALANCING 30 00:23:45.134 08/21/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 31 00:23:45.134 08/21/06 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.16" given by the primary server 32 00:23:45.134 08/21/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 33 00:23:45.144 08/21/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 34 00:23:45.634 08/21/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 1145, dst port 4005 35 00:23:45.634 08/21/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.16, src port 1145, dst port 4005 36 00:23:45.634 08/21/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.16, src port 4005, dst port 1145 37 00:23:45.634 08/21/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.16, src port 1145, dst port 4005 38 00:23:45.634 08/21/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.16" 39 00:23:46.135 08/21/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 40 00:23:46.155 08/21/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.16. 41 00:23:46.175 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.16 42 00:23:46.345 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 43 00:23:46.345 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.16 44 00:23:46.345 08/21/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 45 00:23:46.345 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 46 00:23:46.345 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 47 00:23:46.345 08/21/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 48 00:23:46.365 08/21/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 49 00:23:46.365 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.16 50 00:23:46.365 08/21/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 51 00:23:46.376 08/21/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 52 00:23:46.396 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 53 00:23:46.396 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 54 00:23:46.396 08/21/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 55 00:23:59.766 08/21/06 Sev=Info/4 CM/0x63100017 xAuth application returned 56 00:23:59.766 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 57 00:24:02.461 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 58 00:24:02.461 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 59 00:24:02.461 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 60 00:24:02.461 08/21/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 61 00:24:02.531 08/21/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 62 00:24:02.531 08/21/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 63 00:24:02.531 08/21/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 64 00:24:02.531 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 65 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 66 00:24:03.532 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 67 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.13.6.169 68 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.192.0 69 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 137.69.224.15 70 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.221.12.10 71 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 72 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 73 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas West Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 74 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 75 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 76 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 77 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 78 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_INCLUDE_LOCAL_LAN (# of local_nets), value = 0x00000001 79 00:24:03.532 08/21/06 Sev=Info/5 IKE/0x6300000F LOCAL_NET #1 subnet = 192.168.1.0 mask = 255.255.255.0 protocol = 0 src port = 0 dest port=0 80 00:24:03.552 08/21/06 Sev=Info/4 CM/0x63100019 Mode Config data received 81 00:24:03.562 08/21/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.13.6.169, GW IP = 137.69.115.16, Remote IP = 0.0.0.0 82 00:24:03.562 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 137.69.115.16 83 00:24:03.562 08/21/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 84 00:24:03.562 08/21/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 85 00:24:03.603 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 86 00:24:03.603 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.16 87 00:24:03.603 08/21/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 88 00:24:03.603 08/21/06 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 17 seconds, setting expiry to 86383 seconds from now 89 00:24:03.603 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 90 00:24:03.613 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.16 91 00:24:03.613 08/21/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 92 00:24:03.613 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 137.69.115.16 93 00:24:03.613 08/21/06 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=B0084698 OUTBOUND SPI = 0x046AB8CE INBOUND SPI = 0xD1F2DD94) 94 00:24:03.613 08/21/06 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x046AB8CE 95 00:24:03.613 08/21/06 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0xD1F2DD94 96 00:24:04.303 08/21/06 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.13.6.169/255.255.192.0 DNS=137.69.224.15,128.221.12.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 97 00:24:04.423 08/21/06 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 98 00:24:04.463 08/21/06 Sev=Info/4 CM/0x6310001A One secure connection established 99 00:24:04.493 08/21/06 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.2. Current address(es): 192.168.1.2, 10.13.6.169. 100 00:24:04.503 08/21/06 Sev=Info/4 CM/0x63100038 Address watch added for 10.13.6.169. Current address(es): 192.168.1.2, 10.13.6.169. 101 00:24:04.633 08/21/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 102 00:24:04.633 08/21/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0xceb86a04 into key list 103 00:24:04.633 08/21/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 104 00:24:04.633 08/21/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x94ddf2d1 into key list 105 00:24:04.633 08/21/06 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.13.6.169 106 00:24:08.669 08/21/06 Sev=Info/4 IPSEC/0x63700019 Activate outbound key with SPI=0xceb86a04 for inbound key with SPI=0x94ddf2d1 107 00:28:47.069 08/21/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 1145, dst port 4005 108 00:33:47.501 08/21/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 1145, dst port 4005 109 00:34:40.077 08/21/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 1781607135 110 00:34:40.077 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 111 00:34:40.097 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 112 00:34:40.097 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.16 113 00:34:40.097 08/21/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.16, seq# received = 1781607136, seq# expected = 1781607136 114 00:38:47.563 08/21/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 1145, dst port 4005 115 00:43:48.025 08/21/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.16, src port 1145, dst port 4005 116 00:44:57.615 08/21/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 1781607136 117 00:44:57.615 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 118 00:44:57.635 08/21/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 119 00:44:57.635 08/21/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.16 120 00:44:57.635 08/21/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.16, seq# received = 1781607137, seq# expected = 1781607137 121 00:45:28.209 08/21/06 Sev=Info/4 CM/0x6310000A Secure connections terminated 122 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 123 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 137.69.115.16 124 00:45:28.209 08/21/06 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 46AB8CE INBOUND SPI = D1F2DD94) 125 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=B0084698 126 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=CA6102B2798B98DA R_Cookie=5C7EFE02F3B9E9A9) reason = DEL_REASON_RESET_SADB 127 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.16 128 00:45:28.209 08/21/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=CA6102B2798B98DA R_Cookie=5C7EFE02F3B9E9A9) reason = DEL_REASON_RESET_SADB 129 00:45:28.209 08/21/06 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_RESET_SADB. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 130 00:45:28.209 08/21/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 131 00:45:28.209 08/21/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 132 00:45:28.209 08/21/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 1145 for TCP connection. 133 00:45:28.209 08/21/06 Sev=Info/6 CM/0x63100031 Tunnel to headend device 137.69.115.16 disconnected: duration: 0 days 0:21:24 134 00:45:28.229 08/21/06 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter 135 00:45:30.682 08/21/06 Sev=Info/4 CM/0x63100035 The Virtual Adapter was disabled 136 00:45:30.682 08/21/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 137 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0x94ddf2d1 138 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0x94ddf2d1 139 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0xceb86a04 140 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0xceb86a04 141 00:45:30.692 08/21/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.16, src port 1145, dst port 4005 142 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 143 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 144 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 145 00:45:30.692 08/21/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys