Syslog messages IPsec and IKEv2

Message
IKEv2: Maximum IKE Peers Limit Reached
Explanation

The maximum IKEv2 peer limit is reached on the device.

Message Level

Warning

Message
IKEv2: Recovered from Maximum IKE Peers Limit Condition
Explanation

The device is recovered after reaching the maximum IKEv2 peer limit.

Message Level

Informational

Message
IKEv2: IKEv2 session <up_down> source <source_address> Destination <destination_address> VRF <vrf_id> SPI <spi_id>
Explanation

A state change has occurred for an IKEv2 session.

The up_down is the state of the interface.

The source_address is the source IP address of the IKEv2 session.

The destination address is the destination IP address in the packet.

The vrf_id is the tunnel base VRF.

The spi_id is the security parameter index (SPI) in the packet.

Message Level

Informational

Message
IKEv2: Invalid Message Type Received with Source <source_address> Destination <destination_address> SPI <spi_id> MessageType <x>
Explanation

An invalid IKEv2 message type is received.

The source_address is the source IP address in the packet.

The destination address is the destination IP address in the packet.

The spi_id is the security parameter index (SPI) in the packet.

The x is the value of the unsupported message type in the IKEv2 packet.

Message Level

Informational

Message
IKEv2: Invalid Payload Type Received with Source <source_address> Destination <destination_address> SPI <spi_id> PayloadType <x>
Explanation

A state change has occurred for an IPsec session.

The source_address is the source IP address in the packet.

The destination address is the destination IP address in the packet.

The spi_id is the security parameter index (SPI) in the packet.

The x is the value of the unsupported payload type.

Message Level

Informational

Message
IPsec: IPSec module <module_id> on unit <unit_id> is <up_down>
Explanation

A state change has occurred for an IPsec module. Hot swapping of the module is not supported, but an IPsec module is marked as down when the IPsec module is not usable.

The module_id is the module ID.

The unit_id is the unit ID.

The up_down is the state of the module.

Message Level

Alert

Message
IPsec: IPsec session <up_down> source <source_address> Destination <destination_address> VRF <vrf_id> SPI <spi_id> Direction <direction>
Explanation

A state change has occurred for an IPsec session.

The up_down is the state of the interface.

The source_address is the source IP address of the IPsec session.

The destination address is the destination IP address in the packet.

The vrf_id is the tunnel base VRF.

The spi_id is the security parameter index (SPI) in the packet.

The direction is ingress or egress.

Message Level

Informational