EZD0958I   Unsupported protocol ( protocol_id ) for phase phase Security Association negotiation

Explanation

An IKE negotiation failed because the server encountered a protocol that is not valid in the current Security Association (SA) negotiation phase. Phase 1 negotiation supports only the IKE protocol and phase 2 supports only the ESP and AH protocols.

Additional diagnostic messages that have the same message instance number will be issued to identify the impacted SA. The message instance number precedes the message number in the log output and is used to group related messages from the IKE daemon.

protocol_id is the numerical value that identifies the unsupported protocol.

phase is the phase (1 or 2) that the negotiation was in when the error occurred.

System action

The SA negotiation failed; IKE daemon processing continues.

Operator response

Contact the system programmer.

System programmer response

Notify the administrator of the remote security endpoint about this error and ask the administrator to verify that they are using only the supported protocols for SA negotiations that are listed in Explanation above.

Module

doi.cpp, policy.cpp

Procedure name

None.