EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 15:56:46.288 09/20/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 15:56:46.318 09/20/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 3 15:56:46.318 09/20/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 4 15:56:46.358 09/20/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 3679 for TCP connection. 5 15:56:46.617 09/20/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 6 15:56:46.617 09/20/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 7 15:56:46.617 09/20/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 3679, dst port 4005 8 15:56:46.617 09/20/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 3679 9 15:56:46.617 09/20/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 3679, dst port 4005 10 15:56:46.617 09/20/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 11 15:56:47.107 09/20/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 12 15:56:47.117 09/20/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 13 15:56:47.127 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 14 15:56:47.297 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 15 15:56:47.297 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 16 15:56:47.297 09/20/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 17 15:56:47.297 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 18 15:56:47.297 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 19 15:56:47.297 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 20 15:56:47.327 09/20/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 21 15:56:47.327 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 22 15:56:47.327 09/20/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 23 15:56:47.327 09/20/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 24 15:56:47.357 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 25 15:56:47.357 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 26 15:56:47.357 09/20/06 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.17" from primary server 27 15:56:47.357 09/20/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=E4CBCD94B49EE09F R_Cookie=0E47971CF322B309) reason = DEL_REASON_LOAD_BALANCING 28 15:56:47.357 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 29 15:56:48.106 09/20/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=E4CBCD94B49EE09F R_Cookie=0E47971CF322B309) reason = DEL_REASON_LOAD_BALANCING 30 15:56:48.106 09/20/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 31 15:56:48.106 09/20/06 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.17" given by the primary server 32 15:56:48.106 09/20/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.17" 33 15:56:48.116 09/20/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 34 15:56:49.105 09/20/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 3679, dst port 4005 35 15:56:49.105 09/20/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.17, src port 3679, dst port 4005 36 15:56:49.105 09/20/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.17, src port 4005, dst port 3679 37 15:56:49.105 09/20/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.17, src port 3679, dst port 4005 38 15:56:49.105 09/20/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.17" 39 15:56:49.614 09/20/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.17" 40 15:56:49.614 09/20/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.17. 41 15:56:49.624 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.17 42 15:56:49.804 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 43 15:56:49.804 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.17 44 15:56:49.804 09/20/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 45 15:56:49.804 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 46 15:56:49.804 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 47 15:56:49.804 09/20/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 48 15:56:49.814 09/20/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 49 15:56:49.814 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.17 50 15:56:49.814 09/20/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 51 15:56:49.814 09/20/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 52 15:56:49.844 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 53 15:56:49.844 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 54 15:56:49.844 09/20/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 55 15:56:56.807 09/20/06 Sev=Info/4 CM/0x63100017 xAuth application returned 56 15:56:56.807 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 57 15:56:59.124 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 58 15:56:59.124 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 59 15:56:59.124 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 60 15:56:59.124 09/20/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 61 15:56:59.184 09/20/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 62 15:56:59.194 09/20/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 63 15:56:59.194 09/20/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 64 15:56:59.194 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 65 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 66 15:57:00.103 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 67 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.13.32.188 68 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.192.0 69 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 137.69.224.15 70 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.221.12.10 71 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 72 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 73 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas West Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 74 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 75 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 76 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 77 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 78 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_INCLUDE_LOCAL_LAN (# of local_nets), value = 0x00000001 79 15:57:00.103 09/20/06 Sev=Info/5 IKE/0x6300000F LOCAL_NET #1 subnet = 192.168.1.0 mask = 255.255.255.0 protocol = 0 src port = 0 dest port=0 80 15:57:00.103 09/20/06 Sev=Info/4 CM/0x63100019 Mode Config data received 81 15:57:00.103 09/20/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.13.32.188, GW IP = 137.69.115.17, Remote IP = 0.0.0.0 82 15:57:00.103 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 137.69.115.17 83 15:57:00.163 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 84 15:57:00.163 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.17 85 15:57:00.163 09/20/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 86 15:57:00.163 09/20/06 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 11 seconds, setting expiry to 86389 seconds from now 87 15:57:00.173 09/20/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 88 15:57:00.173 09/20/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.17 89 15:57:00.173 09/20/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 90 15:57:00.173 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 137.69.115.17 91 15:57:00.173 09/20/06 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=89C50E26 OUTBOUND SPI = 0x49D217B8 INBOUND SPI = 0x57659449) 92 15:57:00.173 09/20/06 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x49D217B8 93 15:57:00.173 09/20/06 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0x57659449 94 15:57:02.321 09/20/06 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.13.32.188/255.255.192.0 DNS=137.69.224.15,128.221.12.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 95 15:57:02.361 09/20/06 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 96 15:57:02.501 09/20/06 Sev=Info/4 CM/0x6310001A One secure connection established 97 15:57:02.531 09/20/06 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.4. Current address(es): 192.168.1.4, 10.13.32.188. 98 15:57:02.531 09/20/06 Sev=Info/4 CM/0x63100038 Address watch added for 10.13.32.188. Current address(es): 192.168.1.4, 10.13.32.188. 99 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 100 15:57:02.661 09/20/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 101 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 102 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0xb817d249 into key list 103 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 104 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x49946557 into key list 105 15:57:02.661 09/20/06 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.13.32.188 106 15:57:57.250 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 107 15:57:58.021 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 108 15:57:58.021 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 109 15:57:58.021 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 110 15:57:58.021 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 111 15:57:58.021 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 112 15:57:59.242 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 113 15:57:59.753 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 114 15:57:59.753 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 115 15:58:00.755 09/20/06 Sev=Warning/3 CM/0xA310002C Adapter address changed from 192.168.1.4. Current address(es): 10.13.32.188. 116 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 117 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 137.69.115.17 118 15:58:00.755 09/20/06 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 49D217B8 INBOUND SPI = 57659449) 119 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=89C50E26 120 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=FB0ADAD280C229EC R_Cookie=3031739D2B0E1FE3) reason = DEL_REASON_ADDRESS_CHANGE 121 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.17 122 15:58:00.755 09/20/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=FB0ADAD280C229EC R_Cookie=3031739D2B0E1FE3) reason = DEL_REASON_ADDRESS_CHANGE 123 15:58:00.755 09/20/06 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_ADDRESS_CHANGE. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 124 15:58:00.755 09/20/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 125 15:58:00.755 09/20/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 126 15:58:00.755 09/20/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 3679 for TCP connection. 127 15:58:00.755 09/20/06 Sev=Info/6 CM/0x63100031 Tunnel to headend device 137.69.115.17 disconnected: duration: 0 days 0:0:58 128 15:58:00.895 09/20/06 Sev=Warning/2 CVPND/0xA340000E Failed to get adapter index. 129 15:58:00.895 09/20/06 Sev=Warning/2 CVPND/0xA340000E Failed to get adapter index. 130 15:58:00.895 09/20/06 Sev=Warning/2 CVPND/0xA340000E Failed to get adapter index. 131 15:58:00.905 09/20/06 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter 132 15:58:04.630 09/20/06 Sev=Info/4 CM/0x63100035 The Virtual Adapter was disabled 133 15:58:04.630 09/20/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 134 15:58:04.650 09/20/06 Sev=Warning/2 IPSEC/0xE3700003 Function CniInjectSend() failed with an error code of 0xa4510009 (IPSecDrvCB:824) 135 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0x49946557 136 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0x49946557 137 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0xb817d249 138 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0xb817d249 139 15:58:04.650 09/20/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.17, src port 3679, dst port 4005 140 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 141 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0x00000000 142 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 143 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 144 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 145 15:58:04.650 09/20/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 146 15:58:04.650 09/20/06 Sev=Warning/2 IKE/0xA3000067 Received an IPC message during invalid state (IKE_MAIN:511)