EMC VPN Dialer Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\Program Files\EMC VPN\VPN Client 1 17:23:01.796 03/12/07 Sev=Info/4 CM/0x63100002 Begin connection process 2 17:23:01.826 03/12/07 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 3 17:23:01.826 03/12/07 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 4 17:23:01.846 03/12/07 Sev=Info/6 CM/0x6310002F Allocated local TCP port 1072 for TCP connection. 5 17:23:02.016 03/12/07 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 6 17:23:02.016 03/12/07 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 7 17:23:02.016 03/12/07 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.15, src port 1072, dst port 4005 8 17:23:02.016 03/12/07 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.15, src port 4005, dst port 1072 9 17:23:02.016 03/12/07 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.15, src port 1072, dst port 4005 10 17:23:02.016 03/12/07 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "usvgw3.emc.com" 11 17:23:02.517 03/12/07 Sev=Info/4 CM/0x63100024 Attempt connection with server "usvgw3.emc.com" 12 17:23:02.547 03/12/07 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.15. 13 17:23:02.587 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.15 14 17:23:02.757 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 15 17:23:02.757 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.15 16 17:23:02.757 03/12/07 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 17 17:23:02.757 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 18 17:23:02.757 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports DPD 19 17:23:02.757 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 20 17:23:02.817 03/12/07 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 21 17:23:02.817 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.15 22 17:23:02.817 03/12/07 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 23 17:23:02.817 03/12/07 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 24 17:23:02.857 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.15 25 17:23:02.857 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:LOAD_BALANCE) from 137.69.115.15 26 17:23:02.857 03/12/07 Sev=Info/4 CM/0x6310001B Received alternative server address "137.69.115.17" from primary server 27 17:23:02.857 03/12/07 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=4F028A05255EC77C R_Cookie=8032E8EA164E90DA) reason = DEL_REASON_LOAD_BALANCING 28 17:23:02.857 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.15 29 17:23:03.518 03/12/07 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=4F028A05255EC77C R_Cookie=8032E8EA164E90DA) reason = DEL_REASON_LOAD_BALANCING 30 17:23:03.518 03/12/07 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "usvgw3.emc.com" because of "DEL_REASON_LOAD_BALANCING" 31 17:23:03.518 03/12/07 Sev=Info/4 CM/0x63100010 Try alternative server "137.69.115.17" given by the primary server 32 17:23:03.518 03/12/07 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.17" 33 17:23:03.538 03/12/07 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 34 17:23:04.019 03/12/07 Sev=Info/6 IPSEC/0x63700022 TCP RST sent to 137.69.115.15, src port 1072, dst port 4005 35 17:23:04.019 03/12/07 Sev=Info/6 IPSEC/0x6370001F TCP SYN sent to 137.69.115.17, src port 1072, dst port 4005 36 17:23:04.019 03/12/07 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 137.69.115.17, src port 4005, dst port 1072 37 17:23:04.019 03/12/07 Sev=Info/6 IPSEC/0x63700020 TCP ACK sent to 137.69.115.17, src port 1072, dst port 4005 38 17:23:04.019 03/12/07 Sev=Info/4 CM/0x63100029 TCP connection established on port 4005 with server "137.69.115.17" 39 17:23:04.520 03/12/07 Sev=Info/4 CM/0x63100024 Attempt connection with server "137.69.115.17" 40 17:23:04.540 03/12/07 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 137.69.115.17. 41 17:23:04.560 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Unity)) to 137.69.115.17 42 17:23:04.730 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 43 17:23:04.730 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?), VID(?)) from 137.69.115.17 44 17:23:04.730 03/12/07 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 45 17:23:04.730 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 46 17:23:04.730 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports DPD 47 17:23:04.730 03/12/07 Sev=Info/5 IKE/0x63000001 Peer supports DWR Code and DWR Text 48 17:23:04.750 03/12/07 Sev=Info/6 IKE/0x63000001 IOS Vendor ID Contruction successful 49 17:23:04.750 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 137.69.115.17 50 17:23:04.750 03/12/07 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4 51 17:23:04.750 03/12/07 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 52 17:23:04.780 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 53 17:23:04.780 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 54 17:23:04.780 03/12/07 Sev=Info/4 CM/0x63100015 Launch xAuth application 55 17:23:14.975 03/12/07 Sev=Info/4 CM/0x63100017 xAuth application returned 56 17:23:14.975 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 57 17:23:17.548 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 58 17:23:17.548 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 59 17:23:17.548 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 60 17:23:17.548 03/12/07 Sev=Info/4 CM/0x6310000E Established Phase 1 SA. 1 Crypto Active IKE SA, 1 User Authenticated IKE SA in the system 61 17:23:17.699 03/12/07 Sev=Info/5 IKE/0x6300005D Client sending a firewall request to concentrator 62 17:23:17.699 03/12/07 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=Cisco Systems Integrated Client, Capability= (Centralized Protection Policy). 63 17:23:17.699 03/12/07 Sev=Info/5 IKE/0x6300005C Firewall Policy: Product=NetworkICE BlackICE Defender, Capability= (Are you There?). 64 17:23:17.699 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 137.69.115.17 65 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 66 17:23:18.660 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 137.69.115.17 67 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_ADDRESS: , value = 10.13.32.53 68 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NETMASK: , value = 255.255.192.0 69 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(1): , value = 137.69.224.15 70 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_DNS(2): , value = 128.221.12.10 71 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(1) (a.k.a. WINS) : , value = 128.221.12.10 72 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x63000010 MODE_CFG_REPLY: Attribute = INTERNAL_IPV4_NBNS(2) (a.k.a. WINS) : , value = 128.222.67.10 73 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_BANNER, value = ************** EMC Americas West Coast VPN Gateway ************** ATTENTION!!! If you are running a VPN Client version other than 4.6, you must upgrade as soon as possible. Check the title bar of your VPN Dialer application. If it does not start with VPN Dialer-Version 4.6, disconnect from VPN now and visit http://vpndist.emc.com. Download and install "DTP3.6-VPN4.6.EXE". 74 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_SAVEPWD: , value = 0x00000000 75 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = MODECFG_UNITY_DEFDOMAIN: , value = corp.emc.com 76 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_PFS: , value = 0x00000000 77 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000E MODE_CFG_REPLY: Attribute = APPLICATION_VERSION, value = Cisco Systems, Inc./VPN 3000 Concentrator Version 4.7.2.B built by vmurphy on Oct 04 2005 02:50:52 78 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000D MODE_CFG_REPLY: Attribute = MODECFG_UNITY_INCLUDE_LOCAL_LAN (# of local_nets), value = 0x00000001 79 17:23:18.660 03/12/07 Sev=Info/5 IKE/0x6300000F LOCAL_NET #1 subnet = 192.168.1.0 mask = 255.255.255.0 protocol = 0 src port = 0 dest port=0 80 17:23:18.720 03/12/07 Sev=Info/4 CM/0x63100019 Mode Config data received 81 17:23:18.730 03/12/07 Sev=Info/4 IKE/0x63000055 Received a key request from Driver: Local IP = 10.13.32.53, GW IP = 137.69.115.17, Remote IP = 0.0.0.0 82 17:23:18.730 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 137.69.115.17 83 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 84 17:23:18.770 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.17 85 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 86400 seconds 86 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x63000046 This SA has already been alive for 14 seconds, setting expiry to 86386 seconds from now 87 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 88 17:23:18.770 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK QM *(HASH, SA, NON, ID, ID, NOTIFY:STATUS_RESP_LIFETIME) from 137.69.115.17 89 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x63000044 RESPONDER-LIFETIME notify has value of 28800 seconds 90 17:23:18.770 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK QM *(HASH) to 137.69.115.17 91 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x63000058 Loading IPsec SA (MsgID=20F50283 OUTBOUND SPI = 0x6970BD60 INBOUND SPI = 0xD1E70142) 92 17:23:18.770 03/12/07 Sev=Info/5 IKE/0x63000025 Loaded OUTBOUND ESP SPI: 0x6970BD60 93 17:23:18.780 03/12/07 Sev=Info/5 IKE/0x63000026 Loaded INBOUND ESP SPI: 0xD1E70142 94 17:23:22.025 03/12/07 Sev=Info/4 CM/0x63100034 The Virtual Adapter was enabled: IP=10.13.32.53/255.255.192.0 DNS=137.69.224.15,128.221.12.10 WINS=128.221.12.10,128.222.67.10 Domain=corp.emc.com Split DNS Names= 95 17:23:22.075 03/12/07 Sev=Info/6 CM/0x63100036 The routing table was updated for the Virtual Adapter 96 17:23:22.105 03/12/07 Sev=Info/4 CM/0x6310001A One secure connection established 97 17:23:22.175 03/12/07 Sev=Info/4 CM/0x63100038 Address watch added for 192.168.1.101. Current address(es): 192.168.1.101, 10.13.32.53, 192.168.6.1, 192.168.5.1. 98 17:23:22.185 03/12/07 Sev=Info/4 CM/0x63100038 Address watch added for 10.13.32.53. Current address(es): 192.168.1.101, 10.13.32.53, 192.168.6.1, 192.168.5.1. 99 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 100 17:23:22.455 03/12/07 Sev=Info/6 IPSEC/0x6370002B Sent 8 packets, 0 were fragmented. 101 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 102 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x60bd7069 into key list 103 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x63700010 Created a new key structure 104 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x6370000F Added key with SPI=0x4201e7d1 into key list 105 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x63700019 Activate outbound key with SPI=0x60bd7069 for inbound key with SPI=0x4201e7d1 106 17:23:22.455 03/12/07 Sev=Info/4 IPSEC/0x6370002E Assigned VA private interface addr 10.13.32.53 107 17:26:19.310 03/12/07 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.17, seq# = 2878084062 108 17:26:19.310 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.17 109 17:26:19.330 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 110 17:26:19.330 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.17 111 17:26:19.330 03/12/07 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.17, seq# received = 2878084063, seq# expected = 2878084063 112 17:28:05.472 03/12/07 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.17, src port 1072, dst port 4005 113 17:33:05.924 03/12/07 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.17, src port 1072, dst port 4005 114 17:33:23.960 03/12/07 Sev=Info/6 IKE/0x6300003D Sending DPD request to 137.69.115.17, seq# = 2878084063 115 17:33:23.960 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 137.69.115.17 116 17:33:23.980 03/12/07 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 137.69.115.17 117 17:33:23.980 03/12/07 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK INFO *(HASH, NOTIFY:DPD_ACK) from 137.69.115.17 118 17:33:23.980 03/12/07 Sev=Info/5 IKE/0x6300003F Received DPD ACK from 137.69.115.17, seq# received = 2878084064, seq# expected = 2878084064 119 17:38:06.356 03/12/07 Sev=Info/6 IPSEC/0x63700021 TCP heartbeat sent to 137.69.115.17, src port 1072, dst port 4005 120 08:18:22.161 03/12/07 Sev=Info/4 CM/0x6310000A Secure connections terminated 121 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 122 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 137.69.115.17 123 08:18:22.161 03/12/07 Sev=Info/5 IKE/0x63000018 Deleting IPsec SA: (OUTBOUND SPI = 6970BD60 INBOUND SPI = D1E70142) 124 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=20F50283 125 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=5474B39999201993 R_Cookie=B4DE7775DE342CCB) reason = DEL_REASON_RESET_SADB 126 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK INFO *(HASH, DWR) to 137.69.115.17 127 08:18:22.161 03/12/07 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=5474B39999201993 R_Cookie=B4DE7775DE342CCB) reason = DEL_REASON_RESET_SADB 128 08:18:22.161 03/12/07 Sev=Info/4 CM/0x63100013 Phase 1 SA deleted cause by DEL_REASON_RESET_SADB. 0 Crypto Active IKE SA, 0 User Authenticated IKE SA in the system 129 08:18:22.161 03/12/07 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 130 08:18:22.181 03/12/07 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 4005 131 08:18:22.181 03/12/07 Sev=Info/6 CM/0x63100030 Removed local TCP port 1072 for TCP connection. 132 08:18:22.181 03/12/07 Sev=Info/6 CM/0x63100031 Tunnel to headend device 137.69.115.17 disconnected: duration: 49709 days 21:23:16 133 08:18:22.231 03/12/07 Sev=Info/6 CM/0x63100037 The routing table was returned to orginal state prior to Virtual Adapter 134 08:18:23.893 03/12/07 Sev=Info/4 CM/0x63100035 The Virtual Adapter was disabled 135 08:18:23.893 03/12/07 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv