102 lines
8.4 KiB
HTML
102 lines
8.4 KiB
HTML
|
<?xml version="1.0" encoding="UTF-8"?>
|
||
|
<!DOCTYPE html
|
||
|
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||
|
<html lang="en-us" xml:lang="en-us">
|
||
|
<head>
|
||
|
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
||
|
<meta name="security" content="public" />
|
||
|
<meta name="Robots" content="index,follow" />
|
||
|
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
|
||
|
<meta name="DC.Type" content="concept" />
|
||
|
<meta name="DC.Title" content="Common VPN configuration errors and how to fix them" />
|
||
|
<meta name="abstract" content="This information identifies the most common user errors and provides possible resolutions." />
|
||
|
<meta name="description" content="This information identifies the most common user errors and provides possible resolutions." />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajatroubleshootvpn.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajatcp5b28.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajaitemnotfound.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajaparameternotvalid.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajarksnotfound.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajanoupdate.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajaqretsvrsec.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajacpf9821.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajakeysblank.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajasignondif.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajamonitorblank.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajaconrunafterstop.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajatripledes.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajacolumndisplay.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajafilterrulesnotactive.htm" />
|
||
|
<meta name="DC.Relation" scheme="URI" content="rzajakeycongrpchanges.htm" />
|
||
|
<meta name="copyright" content="(C) Copyright IBM Corporation 2000, 2006" />
|
||
|
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2000, 2006" />
|
||
|
<meta name="DC.Format" content="XHTML" />
|
||
|
<meta name="DC.Identifier" content="rzajacommonerrors" />
|
||
|
<meta name="DC.Language" content="en-us" />
|
||
|
<!-- All rights reserved. Licensed Materials Property of IBM -->
|
||
|
<!-- US Government Users Restricted Rights -->
|
||
|
<!-- Use, duplication or disclosure restricted by -->
|
||
|
<!-- GSA ADP Schedule Contract with IBM Corp. -->
|
||
|
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
|
||
|
<link rel="stylesheet" type="text/css" href="./ic.css" />
|
||
|
<title>Common VPN configuration errors and how to fix them</title>
|
||
|
</head>
|
||
|
<body id="rzajacommonerrors"><a name="rzajacommonerrors"><!-- --></a>
|
||
|
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
|
||
|
<h1 class="topictitle1">Common VPN configuration errors and how to fix them</h1>
|
||
|
<div><p>This information identifies the most common user errors and provides
|
||
|
possible resolutions.</p>
|
||
|
<p>This section describes of some of the more common problems that occur with
|
||
|
VPN, and links you to tips on how to resolve them.</p>
|
||
|
<div class="note"><span class="notetitle">Note:</span> When you configure VPN, you are actually creating several different
|
||
|
configuration objects, each of which VPN requires to enable a connection.
|
||
|
In terms of the VPN GUI, these objects are: The IP Security Policies and the
|
||
|
Secure Connections. So, when this information refers to an object, it is referring
|
||
|
to one or more of these parts of the VPN.</div>
|
||
|
</div>
|
||
|
<div>
|
||
|
<ul class="ullinks">
|
||
|
<li class="ulchildlink"><strong><a href="rzajatcp5b28.htm">VPN error message: TCP5B28</a></strong><br />
|
||
|
When you attempt to activate filter rules on an interface, you get this message: TCP5B28 CONNECTION_DEFINITION order violation</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajaitemnotfound.htm">VPN error message: Item not found</a></strong><br />
|
||
|
When you right-click a VPN object and select either <span class="uicontrol">Properties</span> or <span class="uicontrol">Delete</span>,
|
||
|
you get a message that says, <span class="uicontrol">Item not found</span>.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajaparameternotvalid.htm">VPN error message: PARAMETER PINBUF IS NOT VALID</a></strong><br />
|
||
|
When you attempt to start a connection, you get a message that says, <span class="uicontrol">PARAMETER PINBUF IS NOT VALID...</span></li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajarksnotfound.htm">VPN error message: Item not found, Remote key server...</a></strong><br />
|
||
|
When you select <span class="uicontrol">Properties</span> for a dynamic-key connection, you get an error that says that the server cannot find the remote key server you specified.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajanoupdate.htm">VPN error message: Unable to update the object</a></strong><br />
|
||
|
When you select <span class="uicontrol">OK</span> on the property sheet for a dynamic-key group or manual connection, you get a message that tells you the system cannot update the object.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajaqretsvrsec.htm">VPN error message: Unable to encrypt key...</a></strong><br />
|
||
|
You get a message that says that the system cannot encrypt your keys because the QRETSVRSEC value must be set to 1.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajacpf9821.htm">VPN error message: CPF9821</a></strong><br />
|
||
|
When you try to expand or open the IP Policies container in iSeries™ Navigator,
|
||
|
the CPF9821- Not authorized to program QTFRPRS in QSYS library message appears.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajakeysblank.htm">VPN error: All keys are blank</a></strong><br />
|
||
|
When you view the properties of a manual connection, all preshared keys and the algorithm keys for the connection are blank.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajasignondif.htm">VPN error: Sign-on for a different system appears when using Packet Rules</a></strong><br />
|
||
|
The first time you use the Packet Rules interface in <span class="keyword">iSeries™</span>,
|
||
|
a sign-on display appears for a system other than the current one.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajamonitorblank.htm">VPN error: Blank connection status in iSeries Navigator window</a></strong><br />
|
||
|
A connection has no value in the <span class="uicontrol">Status</span> column
|
||
|
in the <span class="keyword">iSeries™ Navigator</span> window.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajaconrunafterstop.htm">VPN error: Connection has enabled status after you stop it</a></strong><br />
|
||
|
After you stop a connection, the <span class="keyword">iSeries™ Navigator</span> window
|
||
|
indicates that the connection is still enabled.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajatripledes.htm">VPN error: 3DES not a choice for encryption</a></strong><br />
|
||
|
When you are working with an IKE policy transform, data policy transform, or a manual connection, the 3DES encryption algorithm is not a choice.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajacolumndisplay.htm">VPN error: Unexpected columns display in the iSeries Navigator window</a></strong><br />
|
||
|
Set up the columns you want to display in the <span class="keyword">iSeries™ Navigator</span> window
|
||
|
for your VPN connections; then, when you look at it later, different columns
|
||
|
display.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajafilterrulesnotactive.htm">VPN error: Active filter rules fail to deactivate</a></strong><br />
|
||
|
When you try to deactivate the current set of filter rules, the message, <samp class="codeph">The active rules failed to be deactivated</samp> appears in the results window.</li>
|
||
|
<li class="ulchildlink"><strong><a href="rzajakeycongrpchanges.htm">VPN error: The key connection group for a connection changes</a></strong><br />
|
||
|
When you create a dynamic-key connection, you specify a dynamic-key group and an identifier for the remote key server. Later, when you view the properties of the related connection object, the General page of the property sheet displays the same remote key server identifier, but a different dynamic-key group.</li>
|
||
|
</ul>
|
||
|
|
||
|
<div class="familylinks">
|
||
|
<div class="parentlink"><strong>Parent topic:</strong> <a href="rzajatroubleshootvpn.htm" title="Refer to this topic when you experience problems with your VPN connections.">Troubleshoot VPN</a></div>
|
||
|
</div>
|
||
|
</div>
|
||
|
</body>
|
||
|
</html>
|