This causes all current VPN connections to end.
|
|
|
|
TCP8606 The VPN Key Manager could not establish the requested security association for connection, [ connection name]
| The VPN Key Manager could not establish the requested security association due to one of these reason codes: 24 - VPN Key Manager key connection authentication failed. 8300 - Failure occurred during VPN Key Manager key connection negotiations. 8306 - No local preshared key found. 8307 -
No remote IKE phase 1 policy found. 8308 - No remote preshared key found. 8327 - VPN Key Manager key connection negotiations timed out. 8400 -
Failure occurred during VPN Key Manager VPN connection negotiations. 8407 -
No remote IKE phase 2 policy found. 8408 - VPN Key Manager VPN connection negotiations timed out. 8500 or 8509 - VPN Key Manager network error has occurred.
|
- Check the job logs for additional messages.
- Correct the errors and try the request again.
- Use iSeries Navigator to check or correct the VPN policy configuration. Ensure that the dynamic-key group associated with this connection has acceptable values configured.
|
|
|
|
TCP8608 VPN connection, [connection name], could not obtain a NAT address
| This dynamic-key group or data connection specified that network address translation (NAT) be done on one or more addresses, and that failed due to one of these likely reason codes: 1 - Address to apply NAT to is not a single IP address. 2 - All available addresses have been used.
|
- Check the job logs for additional messages.
- Correct the errors and try the request again.
- Use iSeries Navigator to check or correct the VPN policy. Ensure that the dynamic-key group associated with this connection has acceptable values for addresses configured.
|
|
|
|
TCP8620 Local connection endpoint not available
| Could not enable this VPN connections because the local connection endpoint was not available.
|
- Check the job logs for additional messages pertaining to this connection.
- Make sure the local connection endpoint is defined and started by using the NETSTAT OPTION(*IFC) command.
- Correct any errors and try the request again.
|
|
|
|
TCP8621 Local data endpoint to available
| Could not enable this VPN connection because the local data endpoint was not available.
|
- Check the job logs for additional messages pertaining to this connection.
- Make sure the local connection endpoint is defined and started by using the NETSTAT OPTION(*IFC) command.
- Correct any errors and try the request again.
|
|
|
|
TCP8622 Transport encapsulation not permitted with a gateway
| Could not enable this VPN connection because the negotiated policy specified transport encapsulation mode and this connection is defined as a security gateway.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to change the VPN policy associated with this VPN connection.
- Correct any errors and try the request again.
|
|
|
|
TCP8623 VPN connection overlaps with an existing one
| Could not enable this VPN connection because an existing VPN connection is already enabled. This connection has a local data endpoint of, [local data endpoint value] and a remote data endpoint of, [remote data endpoint value].
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to view all enabled connections that have local data endpoints and remote data endpoints overlapping the connection. Change the policy of the existing connection if both connections are required.
- Correct any errors and try the request again.
|
|
|
|
TCP8624 VPN connection not within scope of associated policy filter rule
| Could not enable this VPN connection because the data endpoints are not within the defined policy filter rule.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to display the data endpoint restrictions for this connection or dynamic-key group. If Subset of policy filter or Customize to match policy filter is selected, then check the data endpoints of the connection. These must fit within the active filter rule that has an IPSEC action and a VPN connection name associated with this connection. Change the existing connection's policy or the filter rule to enable this connection.
- Correct any errors and try the request again.
|
|
|
|
TCP8625 VPN connection failed an ESP algorithm check
| Could not enable this VPN connection because the secret key associated with the connection was insufficient.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to display the policy associated with this connection and enter a different secret key.
- Correct any errors and try the request again.
|
|
|
|
TCP8626 VPN connection endpoint is not the same as the data endpoint
| Could not enable this VPN connection because the policy specifies that it is a host, and the VPN connection endpoint is not the same as the data endpoint.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to display the data endpoint restrictions for this connection or dynamic-key group. If Subset of policy filter or Customize to match policy filter is selected, then check the data endpoints of the connection. These must fit within the active filter rule that has an IPSEC action and a VPN connection name associated with this connection. Change the existing connection's policy or the filter rule to enable this connection.
- Correct any errors and try the request again.
|
|
|
|
TCP8628 Policy filter rule not loaded
| The policy filter rule for this connection is not active.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to display the active policy filters. Check the policy filter rule for this connection.
- Correct any errors and try the request again.
|
|
|
|
TCP8629 IP packet dropped for VPN connection
| This VPN connection has VPN NAT configured and the required set of NAT addresses has exceeded the available NAT addresses.
|
- Check the job logs for additional messages pertaining to this connection.
- Use iSeries Navigator to increase the number of NAT addresses assigned for this VPN connection.
- Correct any errors and try the request again.
|
|
|
|
TCP862A PPP connection failed to start
| This VPN connection was associated with a PPP profile. When it was started, an attempt was made to start the PPP profile, but a failure occurred.
|
- Check the job logs for additional messages pertaining to this connection.
- Check the job log associated with the PPP connection.
- Correct any errors and try the request again.
|