EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 04:02:37.036 11/12/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 04:02:37.056 11/12/06 Sev=Warning/2 CVPND/0xA3400011 Error -14 sending packet. Dst Addr: 0xFFFFFFFF, Src Addr: 0xC0A80102 (DRVIFACE:1199). 3 04:02:37.076 11/12/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 4 04:02:37.076 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 5 04:02:37.196 11/12/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 1147 for TCP connection. 6 04:02:37.206 11/12/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 7 04:02:37.206 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 8 04:02:37.206 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 1147, dst port 4005 9 04:02:38.138 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 1147 10 04:02:38.138 11/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 1147, dst port 4005 11 04:02:38.138 11/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 12 04:02:38.638 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 13 04:02:38.668 11/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 14 04:02:38.688 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 15 04:02:38.859 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 16 04:02:38.859 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 17 04:02:38.869 11/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 18 04:02:38.869 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 19 04:02:38.869 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 20 04:02:38.869 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 21 04:02:38.869 11/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 22 04:02:38.869 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 23 04:02:38.869 11/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 24 04:02:38.869 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 25 04:02:38.909 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 26 04:02:38.909 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 27 04:02:38.909 11/12/06 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.16" from primary server 28 04:02:38.909 11/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=32160D67A57284F6 R_Cookie=84970D4574476BC5) reason = DEL_REASON_LOAD_BALANCING 29 04:02:38.909 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 30 04:02:39.640 11/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=32160D67A57284F6 R_Cookie=84970D4574476BC5) reason = DEL_REASON_LOAD_BALANCING 31 04:02:39.640 11/12/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 32 04:02:39.640 11/12/06 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.16" given by the primary server 33 04:02:39.640 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 34 04:02:39.650 11/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 35 04:02:40.141 11/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 1147, dst port 4005 36 04:02:40.141 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.16, src port 1147, dst port 4005 37 04:02:40.141 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.16, src port 4005, dst port 1147 38 04:02:40.141 11/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.16, src port 1147, dst port 4005 39 04:02:40.141 11/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.16" 40 04:02:40.641 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.16" 41 04:02:40.641 11/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.16. 42 04:02:40.651 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.16 43 04:02:40.821 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 44 04:02:40.821 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.16 45 04:02:40.821 11/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 46 04:02:40.821 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 47 04:02:40.821 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 48 04:02:40.821 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 49 04:02:40.831 11/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 50 04:02:40.831 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.16 51 04:02:40.831 11/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 52 04:02:40.831 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 53 04:02:40.862 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 54 04:02:40.862 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 55 04:02:40.862 11/12/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 56 04:02:47.361 11/12/06 Sev=Info/4 CM/0x63100017 xAuth application returned 57 04:02:47.361 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 58 04:02:49.814 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 59 04:02:49.814 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 60 04:02:49.814 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 61 04:02:49.814 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 62 04:02:49.854 11/12/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 63 04:02:49.854 11/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 64 04:02:49.854 11/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 65 04:02:49.864 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.16 66 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 67 04:02:50.856 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.16 68 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.13.6.51 69 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.192.0 70 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 137.69.224.15 71 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.221.12.10 72 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 73 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 74 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas West Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 75 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 76 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 77 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 78 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 79 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_INCLUDE_LOCAL_LAN (# of local_nets), value = 0x00000001 80 04:02:50.856 11/12/06 Sev=Info/5 IKE/0x6300000F LOCAL_NET #1 subnet = 192.168.1.0 mask = 255.255.255.0 protocol = 0 src port = 0 dest port=0 81 04:02:50.876 11/12/06 Sev=Info/4 CM/0x63100019 Mode Config data received 82 04:02:50.886 11/12/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.13.6.51, GW IP = 137.69.115.16, Remote IP = 0.0.0.0 83 04:02:50.886 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 137.69.115.16 84 04:02:51.166 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 85 04:02:51.166 11/12/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 86 04:02:56.164 11/12/06 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 87 04:02:56.164 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(Retransmission) to 137.69.115.16 88 04:02:58.857 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 89 04:02:58.857 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(Retransmission) from 137.69.115.16 90 04:03:01.201 11/12/06 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 91 04:03:01.201 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(Retransmission) to 137.69.115.16 92 04:03:06.679 11/12/06 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 93 04:03:06.679 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(Retransmission) to 137.69.115.16 94 04:03:06.869 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 95 04:03:06.869 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(Retransmission) from 137.69.115.16 96 04:03:11.686 11/12/06 Sev=Info/4 IKE/0x6300002D Phase-2 retransmission count exceeded: MsgID=5896CCE4 97 04:03:11.686 11/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 3362308534 98 04:03:11.686 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 99 04:03:11.686 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 137.69.115.16 100 04:03:11.686 11/12/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=5896CCE4 101 04:03:14.860 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 102 04:03:14.860 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(Retransmission) from 137.69.115.16 103 04:03:16.693 11/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 3362308535 104 04:03:16.693 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 105 04:03:21.700 11/12/06 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.16, seq# = 3362308536 106 04:03:21.700 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.16 107 04:03:22.872 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.16 108 04:03:22.872 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, DWR) from 137.69.115.16 109 04:03:22.872 11/12/06 Sev=Info/4 IKE/0x63000080 Delete Reason Code: 4 --> PEER_DELETE-IKE_DELETE_NO_ERROR. 110 04:03:22.872 11/12/06 Sev=Info/5 IKE/0x6300003C Received a DELETE payload for IKE SA with Cookies: I_Cookie=6D40641971F49436 R_Cookie=A68E9EA319AE300C 111 04:03:22.872 11/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=6D40641971F49436 R_Cookie=A68E9EA319AE300C) reason = PEER_DELETE-IKE_DELETE_NO_ERROR 112 04:03:23.202 11/12/06 Sev=Info/6 IPSEC/0x6370001D TCP RST received from 137.69.115.16, src port 4005, dst port 1147 113 04:03:23.703 11/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=6D40641971F49436 R_Cookie=A68E9EA319AE300C) reason = PEER_DELETE-IKE_DELETE_NO_ERROR 114 04:03:23.703 11/12/06 Sev=Info/4 CM/0x63100012 Phase 1 SA deleted before first Phase 2 SA is up cause by "PEER_DELETE-IKE_DELETE_NO_ERROR". 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 115 04:03:23.703 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw1.emc.com" 116 04:03:23.803 11/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 117 04:03:23.813 11/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.16, src port 1147, dst port 4005 118 04:03:23.813 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 1147, dst port 4005 119 04:03:24.705 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.15, src port 4005, dst port 1147 120 04:03:24.705 11/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 128.221.195.15, src port 1147, dst port 4005 121 04:03:29.211 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 1147, dst port 4005 122 04:03:34.228 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 1147, dst port 4005 123 04:03:34.729 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.15, src port 4005, dst port 1147 124 04:03:39.235 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 1147, dst port 4005 125 04:03:44.243 11/12/06 Sev=Info/4 CM/0x6310002A Unable to establish TCP connection on port 4005 with server "usvgw1.emc.com" 126 04:03:44.243 11/12/06 Sev=Info/4 CM/0x6310000C All connection attempts with backup server failed 127 04:03:44.243 11/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 128 04:03:44.243 11/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 129 04:03:44.243 11/12/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 1147 for TCP connection. 130 04:03:44.243 11/12/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 131 04:03:44.253 11/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 128.221.195.15, src port 1147, dst port 4005 132 04:03:44.253 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 133 04:03:44.253 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 134 04:03:44.253 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 135 04:03:44.253 11/12/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 136 04:04:23.529 11/12/06 Sev=Critical/1 FIREWALL/0xE3A00003 Fatal error trying to start the firewall. The firewall has not been started. 137 04:04:25.622 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys