Contents
Nortel Secure Router 8000 Series
Troubleshooting - VAS
ii
Nortel Networks Inc.
Issue 01.01 (30 March 2009)
2.2 Troubleshooting manual IPSec SA setup.....................................................................................................2-6
2.2.1 Typical networking............................................................................................................................2-6
2.2.2 Configuration notes...........................................................................................................................2-6
2.2.3 Troubleshooting flowchart ..............................................................................................................2-11
2.2.4 Troubleshooting procedure..............................................................................................................2-12
2.3 Troubleshooting ISAKMP SA...................................................................................................................2-14
2.3.1 Typical networking..........................................................................................................................2-14
2.3.2 Configuration notes.........................................................................................................................2-15
2.3.3 Troubleshooting flowchart ..............................................................................................................2-19
2.3.4 Troubleshooting procedure..............................................................................................................2-21
2.4 Troubleshooting SA setup using an IPSec policy template .......................................................................2-24
2.4.1 Typical networking..........................................................................................................................2-24
2.4.2 Configuration notes.........................................................................................................................2-25
2.4.3 Troubleshooting flowchart ..............................................................................................................2-30
2.4.4 Troubleshooting procedure..............................................................................................................2-31
2.5 Troubleshooting NAT traversal in the IPSec tunnel ..................................................................................2-32
2.5.1 Typical networking..........................................................................................................................2-33
2.5.2 Configuration notes.........................................................................................................................2-33
2.5.3 Troubleshooting flowchart ..............................................................................................................2-40
2.5.4 Troubleshooting procedure..............................................................................................................2-41
2.6 Troubleshooting GRE over IPSec or L2TP over IPSec .............................................................................2-42
2.6.1 Typical networking..........................................................................................................................2-42
2.6.2 Configuration notes.........................................................................................................................2-43
2.6.3 Troubleshooting flowchart ..............................................................................................................2-46
2.6.4 Troubleshooting procedure..............................................................................................................2-47
2.7 Troubleshooting cases ...............................................................................................................................2-48
2.8 FAQs..........................................................................................................................................................2-49
2.9 Diagnostic tools.........................................................................................................................................2-50
2.9.1 Display commands ..........................................................................................................................2-50
2.9.2 Debugging commands.....................................................................................................................2-59
3 Firewall troubleshooting ..........................................................................................................3-1
3.1 Firewall........................................................................................................................................................3-2
3.2 Troubleshooting the firewall........................................................................................................................3-2
3.2.1 Networking environment...................................................................................................................3-3
3.2.2 Configuration notes...........................................................................................................................3-3
3.2.3 Diagnostic flowchart .........................................................................................................................3-3
3.2.4 Troubleshooting procedures ..............................................................................................................3-5
3.3 FAQs............................................................................................................................................................3-6
3.4 Diagnostic tools...........................................................................................................................................3-6
4 NAT troubleshooting ................................................................................................................4-1
4.1 NAT.............................................................................................................................................................4-2