EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 12:26:03.000 11/12/06 Sev=Info/4 CM/0x63100002 Begin connection process 2 12:26:03.010 11/12/06 Sev=Warning/2 CVPND/0xA3400011 Error -14 sending packet. Dst Addr: 0xFFFFFFFF, Src Addr: 0xC0A80102 (DRVIFACE:1199). 3 12:26:03.010 11/12/06 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 4 12:26:03.010 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw1.emc.com" 5 12:26:03.030 11/12/06 Sev=Info/6 CM/0x6310002F Allocated local TCP port 4849 for TCP connection. 6 12:26:03.441 11/12/06 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 7 12:26:03.441 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 8 12:26:03.441 11/12/06 Sev=Info/6 IPSEC/0x6370002B Sent 1647 packets, 0 were fragmented. 9 12:26:03.441 11/12/06 Sev=Info/4 IPSEC/0x6370000D Key(s) deleted by Interface (192.168.1.140) 10 12:26:03.441 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.15, src port 4849, dst port 4005 11 12:26:03.441 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.15, src port 4005, dst port 4849 12 12:26:03.441 11/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 128.221.195.15, src port 4849, dst port 4005 13 12:26:03.441 11/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw1.emc.com" 14 12:26:03.941 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw1.emc.com" 15 12:26:03.961 11/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 128.221.195.15. 16 12:26:03.971 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 128.221.195.15 17 12:26:04.222 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.15 18 12:26:04.222 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 128.221.195.15 19 12:26:04.222 11/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 20 12:26:04.222 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 21 12:26:04.222 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 22 12:26:04.222 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 23 12:26:04.232 11/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 24 12:26:04.232 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 128.221.195.15 25 12:26:04.232 11/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 26 12:26:04.232 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 27 12:26:04.332 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.15 28 12:26:04.332 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 128.221.195.15 29 12:26:04.342 11/12/06 Sev=Info/4 CM/0x6310001B Received alternative server address "128.221.195.17" from primary server 30 12:26:04.342 11/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=566EF74D06A73FC5 R_Cookie=5D6D98E80F5C3CC3) reason = DEL_REASON_LOAD_BALANCING 31 12:26:04.342 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 128.221.195.15 32 12:26:04.943 11/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=566EF74D06A73FC5 R_Cookie=5D6D98E80F5C3CC3) reason = DEL_REASON_LOAD_BALANCING 33 12:26:04.943 11/12/06 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw1.emc.com" because of "DEL_REASON_LOAD_BALANCING" 34 12:26:04.943 11/12/06 Sev=Info/4 CM/0x63100010 Try alternative server "128.221.195.17" given by the primary server 35 12:26:04.943 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "128.221.195.17" 36 12:26:04.943 11/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 37 12:26:05.444 11/12/06 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 128.221.195.15, src port 4849, dst port 4005 38 12:26:05.444 11/12/06 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 128.221.195.17, src port 4849, dst port 4005 39 12:26:05.444 11/12/06 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 128.221.195.17, src port 4005, dst port 4849 40 12:26:05.444 11/12/06 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 128.221.195.17, src port 4849, dst port 4005 41 12:26:05.444 11/12/06 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "128.221.195.17" 42 12:26:05.944 11/12/06 Sev=Info/4 CM/0x63100024 Attempt connection with server "128.221.195.17" 43 12:26:05.954 11/12/06 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 128.221.195.17. 44 12:26:05.964 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 128.221.195.17 45 12:26:06.215 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 46 12:26:06.215 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 128.221.195.17 47 12:26:06.215 11/12/06 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 48 12:26:06.215 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 49 12:26:06.215 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DPD 50 12:26:06.215 11/12/06 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 51 12:26:06.225 11/12/06 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 52 12:26:06.225 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 128.221.195.17 53 12:26:06.225 11/12/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 54 12:26:06.225 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 55 12:26:06.335 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 56 12:26:06.335 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.17 57 12:26:06.335 11/12/06 Sev=Info/4 CM/0x63100015 Launch xAuth application 58 12:26:11.663 11/12/06 Sev=Info/4 CM/0x63100017 xAuth application returned 59 12:26:11.663 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.17 60 12:26:16.059 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 61 12:26:16.059 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.17 62 12:26:16.059 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.17 63 12:26:16.059 11/12/06 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 64 12:26:16.489 11/12/06 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 65 12:26:16.489 11/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 66 12:26:16.489 11/12/06 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 67 12:26:16.489 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 128.221.195.17 68 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 69 12:26:17.481 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 128.221.195.17 70 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.4.19.155 71 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.224.0 72 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 128.221.12.10 73 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.222.67.10 74 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 75 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 76 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = *********************** EMC Americas East Coast VPN Gateway *********************** This is a restricted area. Unauthorized Access Prohibited. Access only authorized for EMC Approved Personnel. If you are not authorized by EMC, PLEASE DISCONNECT NOW. 77 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 78 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 79 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 80 12:26:17.481 11/12/06 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.Rel built by vmurphy on Jul 20 2005 10:12:45 81 12:26:17.481 11/12/06 Sev=Info/4 CM/0x63100019 Mode Config data received 82 12:26:17.491 11/12/06 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.4.19.155, GW IP = 128.221.195.17, Remote IP = 0.0.0.0 83 12:26:17.491 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 128.221.195.17 84 12:26:17.601 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 85 12:26:17.601 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 128.221.195.17 86 12:26:17.601 11/12/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 87 12:26:17.601 11/12/06 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 12 seconds, setting expiry to 86388 seconds from now 88 12:26:17.611 11/12/06 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 128.221.195.17 89 12:26:17.611 11/12/06 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 128.221.195.17 90 12:26:17.611 11/12/06 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 91 12:26:17.611 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 128.221.195.17 92 12:26:17.611 11/12/06 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=5157B609 OUTBOUND SPI = 0x017041E1 INBOUND SPI = 0x90FE96C1) 93 12:26:17.611 11/12/06 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x017041E1 94 12:26:17.611 11/12/06 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0x90FE96C1 95 12:26:18.142 11/12/06 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.4.19.155/255.255.224.0 DNS=128.221.12.10,128.222.67.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 96 12:26:18.172 11/12/06 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 97 12:26:18.212 11/12/06 Sev=Info/4 CM/0x6310001A One secure connection established 98 12:26:18.262 11/12/06 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.2. Current address(es): 192.168.1.2, 10.4.19.155. 99 12:26:18.262 11/12/06 Sev=Info/4 CM/0x63100038 Address watch added for 10.4.19.155. Current address(es): 192.168.1.2, 10.4.19.155. 100 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 101 12:26:18.302 11/12/06 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 102 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 103 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0xe1417001 into key list 104 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 105 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0xc196fe90 into key list 106 12:26:18.302 11/12/06 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.4.19.155 107 12:26:20.465 11/12/06 Sev=Info/4 IPSEC/0x63700019 Activate outbound key with SPI=0xe1417001 for inbound key with SPI=0xc196fe90 108 12:30:53.878 11/12/06 Sev=Warning/2 IPSEC/0x6370001E Unexpected TCP control packet received from 128.221.195.17, src port 4005, dst port 4849, flags 10h 109 12:31:06.897 11/12/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 128.221.195.17, src port 4849, dst port 4005 110 12:36:07.329 11/12/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 128.221.195.17, src port 4849, dst port 4005 111 12:41:07.270 11/12/06 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 128.221.195.17, src port 4849, dst port 4005 112 12:45:43.968 11/12/06 Sev=Info/4 CM/0x6310000A Secure connections terminated 113 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 114 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 128.221.195.17 115 12:45:43.968 11/12/06 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 17041E1 INBOUND SPI = 90FE96C1) 116 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=5157B609 117 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=E97B2C38BFA25938 R_Cookie=691CA08DEF359DD3) reason = DEL_REASON_RESET_SADB 118 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 128.221.195.17 119 12:45:43.968 11/12/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=E97B2C38BFA25938 R_Cookie=691CA08DEF359DD3) reason = DEL_REASON_RESET_SADB 120 12:45:43.968 11/12/06 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_RESET_SADB. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 121 12:45:43.968 11/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 122 12:45:43.968 11/12/06 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 123 12:45:43.968 11/12/06 Sev=Info/6 CM/0x63100030 Removed local TCP port 4849 for TCP connection. 124 12:45:43.968 11/12/06 Sev=Info/6 CM/0x63100031 Tunnel to headend device 128.221.195.17 disconnected: duration: 0 days 0:19:25 125 12:45:43.968 11/12/06 Sev=Warning/2 CVPND/0xA3400015 Error with call to IpHlpApi.DLL: DeleteIpForwardEntry, error 87 126 12:45:43.978 11/12/06 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter 127 12:45:45.400 11/12/06 Sev=Info/4 CM/0x63100035 The Virtual Adapter was disabled 128 12:45:45.400 11/12/06 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 129 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0xc196fe90 130 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0xc196fe90 131 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x63700013 Delete internal key with SPI=0xe1417001 132 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x6370000C Key deleted by SPI 0xe1417001 133 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 134 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 135 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 136 12:45:45.410 11/12/06 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 137 12:45:45.410 11/12/06 Sev=Warning/3 CM/0xA310000C State violation caused by CTCP UP EVENT at IDLE STATE