Hi,
yes i asked the customer to check this ... if the ICA is reachable via MPLS and Internet as well ...
i have only received logs from the central VPN gateway ...
for example ... since it is so many ...
208.44.YY.ZZ -> is the remote external IP
192.168.254.XX -> is the remote internal MPLS IP
both are in link selection, in HA, 192.168.254.XX is set to primary.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] New TransportConnection (9765669 Total: 25)
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] UDPConnection::UDPConnection: Enter (copy ctor) peer: 192.168.254.62
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] UDPConnection::UDPConnection: conn.m_txSocket: 0x1b1ee458, 0x1b17fc20.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] GetEntryIsakmpObjectsHash: received ipaddr: 192.168.254.XX as key, found fwobj: FW-USAM
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] extended_log_info_create, entered.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_ROLE_START > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_ROLE_RESPONDER > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] FwIkeResponder: entering
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] FwIkeResponderOnEnter: idRanges NOT USED mine [0-0] peer's [0-0]
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] findSAByPeer: Find SA with cookies 5362e2e0f6a51e6b,30eb62504c4a471e from packet
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] findSAByPeer: ISAKMP SA was found
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ResponderOnEnter: create new p1state
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] GetEntryIsakmpObjectsHash: received ipaddr: 208.44.YY.ZZ as key, found fwobj: FW-USAM
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ResponderOnEnter: set peer ike port to: 500
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ResponderOnEnter: client mode: 0
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] GetEntryIsakmpObjectsHash: received ipaddr: 208.44.YY.ZZas key, found fwobj: FW-USAM
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] GetEntryCommunityHashX: received ipaddr: ZZ.YY.44.208 as key, found community: vpn_USAM-1
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] FindCommonCommunity: Found common community (IPv4 addr=XX.YY.44.208) (vpn_USAM-1) for FW-USAM
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] FwIkeNewPhase2State: Community uses profile custom_profile
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_EXCH_START > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_EXCH_INFORMATION > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_PACKET_START > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_INFO_RESPONDER > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ProcessInfoHeader: peer sent non-encrypted info-exchange while ISAKMP SA exists.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ProcessInfo: enter
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] fwIsakmp_ProcessInfoExc entering
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] -- updatePayloadMap: received payload PA_NOTIFY.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] ProcessInfo: identifyPayloads succeeded.
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] processNotifyPayload: protocol: 1
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] processNotifyPayload: notify type: 20
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] Peer d02c0b1e says: Received Notification from Peer: invalid certificate
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] Received Notification from Peer: invalid certificate
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] extended_log_info_build_reason_from_list: list is empty,
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] isakmpd_log: calling isakmpd_log with original reason=(Phase1 Received Notification from Peer: invalid certificate)
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] GetDAGIP: ID d02c0b1e not in DAIP range
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] CFwdCommStreamLocal::Write called
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45] CFwdCommStreamLocal::Write sent 220 bytes
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_PACKET_END > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_EXCH_END > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] < FWIKE_ROLE_END > Id = 1699451
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] TalkToEngine: Engine RC is << FWIKE_RCV_NOTIFY >>
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] TalkToEngine: received Notification from peer
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: Killing negotiation 1699451 (0x1b1ca478) ...
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: p2state isakmp sess id:
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: machine state -exchange: 0
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: machine state -packet: 0
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: marcipan state: 0
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: status: 0
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: cookieI e0e262536b1ea5f6
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: cookieR 5062eb301e474a4c
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] KillNegotiation: fwisakmp error type: 0, code: 20
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] NegotiationTable::DeleteNegotiation: Invoked for:
[vpnd 23263 4092643232]@FW-BR-MB[8 Jul 13:56:45][tunnel] neg ptr: 1b1ca478 ass: 1b2ac088 wait4: 0
what key words i should search for?