EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 07:20:37.977 10/12/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 07:20:38.027 10/12/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 3 07:20:38.027 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 4 07:20:38.047 10/12/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 1444 for TCP connection. 5 07:20:38.308 10/12/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 6 07:20:38.308 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 7 07:20:38.308 10/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 1444, dst port 4005 8 07:20:38.308 10/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 1444 9 07:20:38.308 10/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 1444, dst port 4005 10 07:20:38.308 10/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 11 07:20:38.808 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 12 07:20:38.838 10/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 13 07:20:38.858 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 14 07:20:39.039 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 15 07:20:39.039 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 16 07:20:39.039 10/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 17 07:20:39.039 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 18 07:20:39.039 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 19 07:20:39.039 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 20 07:20:39.049 10/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 21 07:20:39.049 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 22 07:20:39.049 10/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 23 07:20:39.049 10/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 24 07:20:39.069 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 25 07:20:39.079 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 26 07:20:39.079 10/12/06 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.16" from primary server 27 07:20:39.079 10/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=49C1E56DB2AD4A4D R_Cookie=1A95FF0B57D3B4E8) reason = DEL_REASON_LOAD_BALANCING 28 07:20:39.079 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 29 07:20:39.810 10/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=49C1E56DB2AD4A4D R_Cookie=1A95FF0B57D3B4E8) reason = DEL_REASON_LOAD_BALANCING 30 07:20:39.810 10/12/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 31 07:20:39.810 10/12/06 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.16" given by the primary server 32 07:20:39.810 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 33 07:20:39.810 10/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 34 07:20:40.311 10/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 1444, dst port 4005 35 07:20:40.311 10/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.16, src port 1444, dst port 4005 36 07:20:40.311 10/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.16, src port 4005, dst port 1444 37 07:20:40.311 10/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.16, src port 1444, dst port 4005 38 07:20:40.311 10/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.16" 39 07:20:40.811 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 40 07:20:40.811 10/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.16. 41 07:20:40.821 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.16 42 07:20:41.001 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 43 07:20:41.001 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.16 44 07:20:41.001 10/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 45 07:20:41.001 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 46 07:20:41.001 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 47 07:20:41.001 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 48 07:20:41.012 10/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 49 07:20:41.012 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.16 50 07:20:41.012 10/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 51 07:20:41.012 10/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 52 07:20:41.042 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 53 07:20:41.042 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 54 07:20:41.042 10/12/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 55 07:20:57.495 10/12/06 Sev=Info/4 CM/0x63100017 xAuth application returned 56 07:20:57.495 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 57 07:20:57.836 10/12/06 Sev=Info/6 IPSEC/0x6370001D TCP RST received from 137.69.115.16, src port 4005, dst port 1444 58 07:21:59.083 10/12/06 Sev=Info/4 CM/0x63100006 Abort connection attempt before Phase 1 SA up 59 07:21:59.083 10/12/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 60 07:21:59.083 10/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=77AE22CF75C6D61B R_Cookie=DEB682912D25C1F3) reason = DEL_REASON_RESET_SADB 61 07:21:59.083 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.16 62 07:21:59.083 10/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=77AE22CF75C6D61B R_Cookie=DEB682912D25C1F3) reason = DEL_REASON_RESET_SADB 63 07:21:59.083 10/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 64 07:21:59.083 10/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 65 07:21:59.083 10/12/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 1444 for TCP connection. 66 07:21:59.423 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 67 07:21:59.423 10/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.16, src port 1444, dst port 4005 68 07:21:59.423 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 69 07:21:59.423 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 70 07:21:59.423 10/12/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 71 07:22:15.727 10/12/06 Sev=Info/4 CM/0x63100002 Begin connection process 72 07:22:15.737 10/12/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 73 07:22:15.737 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw1.emc.com" 74 07:22:15.757 10/12/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 1455 for TCP connection. 75 07:22:15.947 10/12/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 76 07:22:15.947 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 77 07:22:15.947 10/12/06 Sev=Info/6 IPSEC/0x6370002B Sent 7 packets, 0 were fragmented. 78 07:22:15.947 10/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 1455, dst port 4005 79 07:22:15.947 10/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.15, src port 4005, dst port 1455 80 07:22:15.947 10/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 128.221.195.15, src port 1455, dst port 4005 81 07:22:15.947 10/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw1.emc.com" 82 07:22:16.448 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw1.emc.com" 83 07:22:16.458 10/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 128.221.195.15. 84 07:22:16.468 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 128.221.195.15 85 07:22:16.708 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.15 86 07:22:16.708 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 128.221.195.15 87 07:22:16.708 10/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 88 07:22:16.708 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 89 07:22:16.708 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 90 07:22:16.708 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 91 07:22:16.718 10/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 92 07:22:16.718 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 128.221.195.15 93 07:22:16.718 10/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 94 07:22:16.718 10/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 95 07:22:16.808 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.15 96 07:22:16.808 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 128.221.195.15 97 07:22:16.808 10/12/06 Sev=Info/4 CM/0x6310001B Received alternative server address "128.221.195.16" from primary server 98 07:22:16.808 10/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=3B319218171F34E3 R_Cookie=C409E75A11B65CF6) reason = DEL_REASON_LOAD_BALANCING 99 07:22:16.808 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 128.221.195.15 100 07:22:17.449 10/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=3B319218171F34E3 R_Cookie=C409E75A11B65CF6) reason = DEL_REASON_LOAD_BALANCING 101 07:22:17.449 10/12/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw1.emc.com" because of "DEL_REASON_LOAD_BALANCING" 102 07:22:17.449 10/12/06 Sev=Info/4 CM/0x63100010 Try alternative server "128.221.195.16" given by the primary server 103 07:22:17.449 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "128.221.195.16" 104 07:22:17.449 10/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 105 07:22:17.950 10/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 128.221.195.15, src port 1455, dst port 4005 106 07:22:17.950 10/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.16, src port 1455, dst port 4005 107 07:22:17.950 10/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.16, src port 4005, dst port 1455 108 07:22:17.950 10/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 128.221.195.16, src port 1455, dst port 4005 109 07:22:17.950 10/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "128.221.195.16" 110 07:22:18.451 10/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "128.221.195.16" 111 07:22:18.461 10/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 128.221.195.16. 112 07:22:18.461 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 128.221.195.16 113 07:22:18.701 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 114 07:22:18.701 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 128.221.195.16 115 07:22:18.701 10/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 116 07:22:18.701 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 117 07:22:18.701 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 118 07:22:18.701 10/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 119 07:22:18.711 10/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 120 07:22:18.711 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 128.221.195.16 121 07:22:18.711 10/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 122 07:22:18.711 10/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 123 07:22:18.811 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 124 07:22:18.811 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.16 125 07:22:18.811 10/12/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 126 07:22:31.589 10/12/06 Sev=Info/4 CM/0x63100017 xAuth application returned 127 07:22:31.589 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.16 128 07:22:34.013 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 129 07:22:34.013 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.16 130 07:22:34.013 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.16 131 07:22:34.013 10/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 132 07:22:34.083 10/12/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 133 07:22:34.083 10/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 134 07:22:34.083 10/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 135 07:22:34.083 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.16 136 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 137 07:22:35.185 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.16 138 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.4.13.143 139 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.224.0 140 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 128.221.12.10 141 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.222.67.10 142 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 143 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 144 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas East Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 145 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 146 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 147 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 148 07:22:35.185 10/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 149 07:22:35.185 10/12/06 Sev=Info/4 CM/0x63100019 Mode Config data received 150 07:22:35.195 10/12/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.4.13.143, GW IP = 128.221.195.16, Remote IP = 0.0.0.0 151 07:22:35.195 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 128.221.195.16 152 07:22:35.305 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 153 07:22:35.305 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 128.221.195.16 154 07:22:35.305 10/12/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 155 07:22:35.305 10/12/06 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 17 seconds, setting expiry to 86383 seconds from now 156 07:22:35.315 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 157 07:22:35.315 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 128.221.195.16 158 07:22:35.315 10/12/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 159 07:22:35.315 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 128.221.195.16 160 07:22:35.315 10/12/06 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=6C512B36 OUTBOUND SPI = 0x07D7190D INBOUND SPI = 0xBCC45C46) 161 07:22:35.315 10/12/06 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x07D7190D 162 07:22:35.315 10/12/06 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0xBCC45C46 163 07:22:37.187 10/12/06 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.4.13.143/255.255.224.0 DNS=128.221.12.10,128.222.67.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 164 07:22:37.207 10/12/06 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 165 07:22:37.237 10/12/06 Sev=Info/4 CM/0x6310001A One secure connection established 166 07:22:37.257 10/12/06 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.4. Current address(es): 192.168.1.4, 10.4.13.143. 167 07:22:37.257 10/12/06 Sev=Info/4 CM/0x63100038 Address watch added for 10.4.13.143. Current address(es): 192.168.1.4, 10.4.13.143. 168 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 169 07:22:37.407 10/12/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 170 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 171 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x0d19d707 into key list 172 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 173 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x465cc4bc into key list 174 07:22:37.407 10/12/06 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.4.13.143 175 07:22:38.478 10/12/06 Sev=Info/4 IPSEC/0x63700019 Activate outbound key with SPI=0x0d19d707 for inbound key with SPI=0x465cc4bc 176 07:24:10.110 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426288 177 07:24:10.110 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 178 07:24:15.117 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426289 179 07:24:15.117 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 180 07:24:15.258 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 181 07:24:15.258 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 182 07:24:15.258 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426290, seq# expected = 2757426290 183 07:25:00.683 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426290 184 07:25:00.683 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 185 07:25:00.793 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 186 07:25:00.793 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 187 07:25:00.793 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426291, seq# expected = 2757426291 188 07:25:21.212 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426291 189 07:25:21.212 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 190 07:25:21.313 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 191 07:25:21.313 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 192 07:25:21.313 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426292, seq# expected = 2757426292 193 07:27:18.902 10/12/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 128.221.195.16, src port 1455, dst port 4005 194 07:27:27.414 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426292 195 07:27:27.414 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 196 07:27:27.514 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 197 07:27:27.514 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 198 07:27:27.514 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426293, seq# expected = 2757426293 199 07:29:18.073 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426293 200 07:29:18.073 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 201 07:29:18.183 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 202 07:29:18.183 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 203 07:29:18.183 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426294, seq# expected = 2757426294 204 07:32:19.844 10/12/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 128.221.195.16, src port 1455, dst port 4005 205 07:34:11.004 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426294 206 07:34:11.004 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 207 07:34:11.114 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 208 07:34:11.114 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 209 07:34:11.114 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426295, seq# expected = 2757426295 210 07:34:21.519 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426295 211 07:34:21.519 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 212 07:34:21.630 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 213 07:34:21.630 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 214 07:34:21.630 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426296, seq# expected = 2757426296 215 07:35:07.085 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426296 216 07:35:07.085 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 217 07:35:07.195 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 218 07:35:07.195 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 219 07:35:07.195 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426297, seq# expected = 2757426297 220 07:35:22.607 10/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 128.221.195.16, seq# = 2757426297 221 07:35:22.607 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 128.221.195.16 222 07:35:22.727 10/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.16 223 07:35:22.727 10/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 128.221.195.16 224 07:35:22.727 10/12/06 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 128.221.195.16, seq# received = 2757426298, seq# expected = 2757426298 225 07:35:42.175 10/12/06 Sev=Info/4 CM/0x6310000A Secure connections terminated 226 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 227 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 128.221.195.16 228 07:35:42.175 10/12/06 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 7D7190D INBOUND SPI = BCC45C46) 229 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=6C512B36 230 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=76F6000A44B22790 R_Cookie=09910FABC4E8BBDE) reason = DEL_REASON_RESET_SADB 231 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 128.221.195.16 232 07:35:42.175 10/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=76F6000A44B22790 R_Cookie=09910FABC4E8BBDE) reason = DEL_REASON_RESET_SADB 233 07:35:42.175 10/12/06 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_RESET_SADB. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 234 07:35:42.175 10/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 235 07:35:42.175 10/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 236 07:35:42.175 10/12/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 1455 for TCP connection. 237 07:35:42.175 10/12/06 Sev=Info/6 CM/0x63100031 Tunnel to headend device 128.221.195.16 disconnected: duration: 0 days 0:13:5 238 07:35:42.185 10/12/06 Sev=Warning/2 CVPND/0xA3400015 Error with call to IpHlpApi.DLL: DeleteIpForwardEntry, error 87 239 07:35:42.185 10/12/06 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter 240 07:35:44.318 10/12/06 Sev=Info/4 CM/0x63100035 The Virtual Adapter was disabled 241 07:35:44.318 10/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 242 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0x465cc4bc 243 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0x465cc4bc 244 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0x0d19d707 245 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0x0d19d707 246 07:35:44.318 10/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 128.221.195.16, src port 1455, dst port 4005 247 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 248 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 249 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 250 07:35:44.318 10/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys