Page 3 - Nortel Networks Inc. software license agreement
3 Nortel VPN Router Troubleshooting — Server Portions of the code in this software product may be Copyright © 1988, Regents of the University of California. All rights reserved. Redistribution and use in source and binary forms of such portions are permitted, provided that the above copyright notice...
Page 5 - Contents
5 Nortel VPN Router Troubleshooting — Server Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Before you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 T...
Page 11 - Preface; Before you begin; This guide uses the following text conventions:
11 Nortel VPN Router Troubleshooting — Server Preface This guide provides information about how to manage and troubleshoot the Nortel VPN Router. Before you begin This guide is for network managers who monitor and maintain the Nortel VPN Router. This guide assumes that you have experience with syste...
Page 12 - italic text; Status
12 Preface NN46110-602 02.01 braces ({}) Indicate required elements in syntax descriptions where there is more than one option. You must choose only one of the options. Do not type the braces when entering the command.Example: If the command syntax is ldap-server source {external | internal} , you m...
Page 13 - or
Preface 13 Nortel VPN Router Troubleshooting — Server vertical line ( | ) Separates choices for command keywords and arguments. Enter only one of the choices. Do not type the vertical line when entering the command.Example: If the command syntax is terminal paging { off | on } , you enter either ter...
Page 14 - Related publications
14 Preface NN46110-602 02.01 Related publications For more information about the Nortel VPN Router, see the following publications: • Release notes provide the latest information, including brief descriptions of the new features, problems fixed in this release, and known problems and workarounds. • ...
Page 15 - Hard-copy technical manuals; , find the product for; How to get help; Finding the latest updates on the Nortel Web site
Preface 15 Nortel VPN Router Troubleshooting — Server Hard-copy technical manuals You can print selected technical manuals and release notes free, directly from the Internet. Go to www.nortelnetworks.com/documentation , find the product for which you need documentation, then locate the specific cate...
Page 16 - Help from the Nortel Web site; download software, documentation, and product bulletins; Help over the phone from a Nortel Solutions Center
16 Preface NN46110-602 02.01 Help from the Nortel Web site The best way to get technical support for Nortel products is from the Nortel Technical Support Web site: www.nortel.com/support This site provides quick access to software, documentation, bulletins, and tools to address issues with Nortel pr...
Page 17 - Getting help through a Nortel distributor or reseller
Preface 17 Nortel VPN Router Troubleshooting — Server Getting help through a Nortel distributor or reseller If you purchased a service contract for your Nortel product from a distributor or authorized reseller, contact the technical support staff for that distributor or reseller.
Page 19 - New in this release; The following sections detail what’s new in; Features; Branch office NAT Traversal
19 Nortel VPN Router Troubleshooting — Server New in this release The following sections detail what’s new in Nortel VPN Router Troubleshooting — Server (NN46110-602) for Release 8.0: • “Features” on page 19 • “Other changes” on page 21 Features See the following sections for information about featu...
Page 21 - Supported software and hardware; “Supported software and hardware” on page 23; Two factor authentication; “Branch office connection problems” on page 104; Other changes; “Removed content” on page 21; Removed content
New in this release 21 Nortel VPN Router Troubleshooting — Server Supported software and hardware This document includes a matrix of features by release. For more information, see “Supported software and hardware” on page 23 . Two factor authentication Release 8.0 includes two factor authentication ...
Page 22 - Nortel VPN Router Troubleshooting — Client; Restructured content; Nortel VPN Router Troubleshooting
22 New in this release NN46110-602 02.01 • Simple Network Management Protocol (SNMP) • system shutdown • automatic backups • disabling new logons • PPP configuration and options The following topics are moved to Nortel VPN Router Troubleshooting — Client (NN46110-700): • Diagnosing client connectivi...
Page 23 - VPN Router Release 8.0 supports the following hardware platforms:
23 Nortel VPN Router Troubleshooting — Server Chapter 1Troubleshooting fundamentals This chapter provides basic information to assist in troubleshooting. This chapter includes the following topics: • “Supported software and hardware” on page 23 • “PCAP” on page 33 • “Hardware LEDs” on page 40 Suppor...
Page 33 - PCAP; Two options exist when you capture packets:
Chapter 1 Troubleshooting fundamentals 33 Nortel VPN Router Troubleshooting — Server PCAP The Packet Capture tool (PCAP) is a troubleshooting tool that you use, in conjunction with other tools such as statistics, logging, network analyzers, and testers, to remotely troubleshoot the VPN Router and ne...
Page 34 - Nortel VPN Router Administration; PCAP features; The VPN Router uses PCAP to perform the following tasks:
34 Chapter 1 Troubleshooting fundamentals NN46110-602 02.01 PCAP initially occurs to the RAM buffer. A low priority task writes the RAM buffer to disk files, called the disk capture files. Although you can configure the maximum size of this file, PCAP can continue to write the captured data. You spe...
Page 35 - Security features; openpcap; File format
Chapter 1 Troubleshooting fundamentals 35 Nortel VPN Router Troubleshooting — Server • limit the traffic that the filters capture • automatically start and stop packet capture with triggers Security features Packet capture on the VPN Router provides the following features to enhance security: • Pack...
Page 36 - Capture types; Physical interface captures
36 Chapter 1 Troubleshooting fundamentals NN46110-602 02.01 Capture types The VPN Router captures packets from the following sources: • physical interfaces, including the following — Asynchronous digital subscriber line (ADSL) or asynchronous transfer mode (ATM) — Fast Ethernet and Gigabit Ethernet,...
Page 37 - IP address of the remote peer on the tunnel session; Global IP captures; “Filters and triggers” on page 38
Chapter 1 Troubleshooting fundamentals 37 Nortel VPN Router Troubleshooting — Server The router encapsulates tunnel captures saved to disk with raw IP encapsulation. When you convert these files to file formats that do not support raw IP encapsulation (including Sniffer), you need Layer 2 encapsulat...
Page 38 - Filters and triggers; Capture filters; If capture objects for physical interfaces or tunnels run at the
38 Chapter 1 Troubleshooting fundamentals NN46110-602 02.01 A global IP capture object captures packets starting from the IP header; the capture object does not save Layer 2 header information in the capture file. Because the router captures both encrypted and decrypted packets, global IP packet cap...
Page 39 - Memory considerations
Chapter 1 Troubleshooting fundamentals 39 Nortel VPN Router Troubleshooting — Server • A stop trigger causes the system to stop saving traffic in the capture buffer after the system encounters a specific packet that matches the stop trigger. The packet capture object, however, does not fully stop. A...
Page 40 - You can display the same information by entering the command; Performance considerations; Hardware LEDs; “Status and logging” on page 81
40 Chapter 1 Troubleshooting fundamentals NN46110-602 02.01 You can display the same information by entering the command show status statistics resources memory . Performance considerations Running packet capture can affect VPN Router performance. You can run only one capture object at a time for a ...
Page 41 - The following table identifies the LEDs on a VPN Router 600.
Chapter 1 Troubleshooting fundamentals 41 Nortel VPN Router Troubleshooting — Server The following table identifies the LEDs on a VPN Router 600. If the Boot LED and the Ready LED light at the same time, the Nortel VPN Router 600 is in recovery mode. The following table identifies the LEDs on a VPN ...
Page 42 - The following table identifies the LEDs on a VPN Router 1600.
42 Chapter 1 Troubleshooting fundamentals NN46110-602 02.01 The following table identifies the LEDs on a VPN Router 1600. The following table identifies the LEDs on a VPN Router 1700, 1740, and 1750. Table 4 Nortel VPN Router 1600 LEDs LED Condition Indicates Nortel logo Blue The power is on. Off Th...
Page 51 - For more information, see the following sections:; Standard tools; Ping; The following list explains the command parameters:
51 Nortel VPN Router Troubleshooting — Server Chapter 2Troubleshooting tools The VPN Router supports standard IP tools such as ping, Traceroute, and Address Resolution Protocol (ARP) show and delete. You access these tools through the Admin , Tools window. You can also use special tools beyond the s...
Page 52 - Traceroute
52 Chapter 2 Troubleshooting tools NN46110-602 02.01 • IP address—the address to ping • 1–999—(Optional) the number of echo requests to return • 1–4048—(Optional) the size of the ping request packet • source address|source hostname—(Optional) the source address or hostname of the outgoing ping reque...
Page 53 - Provide the necessary details in the; Trace Route; Click; mtrace; For more information, see Figure 1
Chapter 2 Troubleshooting tools 53 Nortel VPN Router Troubleshooting — Server 2 Provide the necessary details in the Trace Route section. 3 Click Traceroute . mtrace The multicast traceroute (mtrace) tool is a multicast diagnostic tool that uses special Internet Group Management Protocol (IGMP) pack...
Page 56 - ARP
56 Chapter 2 Troubleshooting tools NN46110-602 02.01 The default number of maximum hops is 32. • resp-ttl—(Optional) time-to-live (TTL) to use for the multicast response on the response packet The default response TTL is 64. • verbose—(Optional) show additional statistics like the route that forward...
Page 57 - ARP Delete; Configuring core dump retrieval on diskless routers
Chapter 2 Troubleshooting tools 57 Nortel VPN Router Troubleshooting — Server 3 Click ARP Delete . Client-based tools IPsec VPN Client Monitor provides network statistics on device, connection, and network errors that help monitor traffic flow and assess IPsec connection performance. Statistic count...
Page 58 - Nortel VPN Router Using the Command; Enabling packet capture on a VPN Router
58 Chapter 2 Troubleshooting tools NN46110-602 02.01 1 Choose Admin , Administrator . The Administrator window appears. 2 In the FTP Coredump section, select Enabled . 3 In the Host box, type the FTP server IP address. 4 In the Path box, type the directory path where you want to save the core dump f...
Page 59 - Enter; The Welcome window appears.; The serial main menu appears.; Access the command line interface by typing the letter
Chapter 2 Troubleshooting tools 59 Nortel VPN Router Troubleshooting — Server 5 On the PC, start HyperTerminal or another terminal emulation program, and then press Enter . The Welcome window appears. Welcome to the VPN Router Copyright (c) 2007 Nortel Networks Ltd. Version: V04_90.185 Creation date...
Page 60 - Saving captured data; “Starting, stopping, and saving capture objects” on page 67
60 Chapter 2 Troubleshooting tools NN46110-602 02.01 The User EXEC prompt appears: CES> 8 Enter Privileged EXEC mode. CES> enable Password:***** 9 Enable packet capture globally on the VPN Router and create the capture password. Use this password to open capture files with the openpcap utility...
Page 61 - Capturing packets to disk file; Nortel VPN Router; Setting the PCAP file path; Setting the size of the RAM buffer
Chapter 2 Troubleshooting tools 61 Nortel VPN Router Troubleshooting — Server Capturing packets to disk file To configure PCAP, you must first enter CLI Capture Configuration mode. For more information about CLI Capture Configuration mode, see Nortel VPN Router Using the Command Line Interface (NN46...
Page 62 - where size is the size of the RAM buffer.; Setting the size of a disk capture file; where max_size is the size of the capture file.; Setting the maximum number of disk capture files
62 Chapter 2 Troubleshooting tools NN46110-602 02.01 where size is the size of the RAM buffer. For example, enter CES(capture-ethernet) #buffersize 1048576 Setting the size of a disk capture file To configure the size of the disk capture file, from CLI Capture Configuration mode enter the following ...
Page 63 - Configure and run packet capture objects; Nortel VPN Router Using the; Creating a capture object; “Capture types” on page 36
Chapter 2 Troubleshooting tools 63 Nortel VPN Router Troubleshooting — Server or No capture-all For example, enter CES(capture-ethernet) #capture-all Configure and run packet capture objects This section provides instructions to create, configure, start, and stop capture objects, as well as instruct...
Page 64 - Configuring a capture object
64 Chapter 2 Troubleshooting tools NN46110-602 02.01 In the following example, you create a capture object called test_ethernet1 that captures traffic on Ethernet interface 1/2. CES# capture add test_ethernet1 FastEthernet 1/2 CES# In the following example, you create a capture object called test_tu...
Page 65 - Edit one or more parameters as required.
Chapter 2 Troubleshooting tools 65 Nortel VPN Router Troubleshooting — Server 2 Display all parameters that you can configure for that type of capture object. CES(capture-ethernet)# ? Packet capture mode direction Captures in one direction exit Exits capture mode filter Applies interface traffic fil...
Page 66 - Tunnel capture parameters; , navigates to Capture Configuration mode, and
66 Chapter 2 Troubleshooting tools NN46110-602 02.01 Tunnel capture parameters Capture objects for tunnels use several unique parameters. The following example creates a tunnel object called bot1 , navigates to Capture Configuration mode, and displays the commands for tunnel objects. The bold comman...
Page 67 - Global IP parameters; rawip; Starting, stopping, and saving capture objects; Displaying capture status
Chapter 2 Troubleshooting tools 67 Nortel VPN Router Troubleshooting — Server Global IP parameters The configurable parameters for the global IP capture object are the same as the parameters available for physical interface objects. The following example creates a global capture object called rawip ...
Page 68 - In the following example, the; command is run with no object; command for a specific capture object.
68 Chapter 2 Troubleshooting tools NN46110-602 02.01 In the following example, the show capture command is run with no object name to display a list of all the capture objects configured on the VPN Router. CES# show capture Name Type Size Buffer use Count State bot1 TUNNEL 1048576 0% 0 EMPTY ether0 ...
Page 69 - Sample packet capture configurations; Interface capture object using a filter and direction; Capture Configuration
Chapter 2 Troubleshooting tools 69 Nortel VPN Router Troubleshooting — Server Sample packet capture configurations This section provides sample configurations and the commands used to create them. Interface capture object using a filter and direction In the following example, you configure a capture...
Page 70 - To stop the capture and save the buffer contents to a file called; Interface capture object using triggers; In the following example, you configure a capture object called
70 Chapter 2 Troubleshooting tools NN46110-602 02.01 To view the status of the running capture object, as well as its configuration, use the show capture command. In this example, the buffer captures 20 frames. CES# show capture test-filter-in Capture state: RUNNING Capture buffer size: 1048576 Capt...
Page 72 - After Telnet traffic activates the stop trigger, the; command
72 Chapter 2 Troubleshooting tools NN46110-602 02.01 CES# show capture test-trigger Capture state: RUNNING Capture buffer size: 1048576 Capture type: ETHERNET Capturing on interface: FastEthernet 0/1 Promiscuous mode is: DISABLED Capturing MAX octets per frame: 4096 Captured frames: 107 Capture buff...
Page 73 - Tunnel capture object using a remote IP address
Chapter 2 Troubleshooting tools 73 Nortel VPN Router Troubleshooting — Server To stop the capture object and save the buffer contents to a file called test4.cap , enter the following commands: CES# capture test-trigger stop CES# capture test-trigger save test4.cap Saving capture test-trigger to file...
Page 74 - View a packet capture output file on a PC; Installing Ethereal software; Download; Saving, downloading, and viewing PCAP files
74 Chapter 2 Troubleshooting tools NN46110-602 02.01 View a packet capture output file on a PC After you save a capture buffer to a file on the VPN Router disk, download the file to a workstation, and analyze the contents offline using one of many available tools. The VPN Router does not provide uti...
Page 75 - “Enabling packet capture on a VPN Router” on page 58; Ethereal; Viewing a PCAP file with Sniffer Pro; “Viewing a PCAP file with Sniffer Pro” on page 75
Chapter 2 Troubleshooting tools 75 Nortel VPN Router Troubleshooting — Server 3 On the VPN Router, stop the packet capture object and save the output to a file, for example CES# capture ethernet1 stop CES# capture ethernet1 save ethernet.cap Saving capture ethernet to file /ide0/ethernet.cap please ...
Page 76 - “Installing Ethereal; Protocol Forcing
76 Chapter 2 Troubleshooting tools NN46110-602 02.01 1 Install Ethereal software (for more information, see “Installing Ethereal software” on page 74 ). 2 Save the packet capture file and download it to the PC as described in steps 1 to 6 of “Saving, downloading, and viewing PCAP files” on page 74 ....
Page 77 - Deleting capture objects and disabling packet capture; “Enabling packet capture
Chapter 2 Troubleshooting tools 77 Nortel VPN Router Troubleshooting — Server Deleting capture objects and disabling packet capture After you no longer need a capture object, delete it to free memory. You can also disable packet capture globally to remove all configured capture objects, and free the...
Page 78 - TunnelGuard tools
78 Chapter 2 Troubleshooting tools NN46110-602 02.01 TunnelGuard tools You can use several sources of information when you initially configure or troubleshoot TunnelGuard. TunnelGuard places an icon in the system tray. If a status message exists because a Software Requirement Set (SRS) check failed,...
Page 79 - Other tools; “Troubleshooting tools” on page 79; System configuration; File management; Use the Admin
Chapter 2 Troubleshooting tools 79 Nortel VPN Router Troubleshooting — Server Other tools Table 12 “Troubleshooting tools” on page 79 lists the tools that you can use to diagnose connectivity problems from Windows NT, Windows 2000, and Windows XP workstations. System configuration Use the Admin , Co...
Page 81 - This chapter includes the following topics:; Introduction; security log
81 Nortel VPN Router Troubleshooting — Server Chapter 3Status and logging The Status windows show which users log on, their traffic demands, and a summary of the VPN Router hardware configuration, including available memory and disk space. This chapter includes the following topics: • “Introduction”...
Page 82 - Normal; Sessions
82 Chapter 3 Status and logging NN46110-602 02.01 The event log captures real-time logging over a relatively short period of time (for example, the event log can wrap 2000 possible entries in minutes). The system log captures data over a longer period of time, up to 61 days. Most events log to the e...
Page 83 - System
Chapter 3 Status and logging 83 Nortel VPN Router Troubleshooting — Server At midnight (12:00 a.m.), the data collection task performs summary calculations and rewrites history files, along with other management and cleanup functions. To perform this task, leave the VPN Router running overnight. The...
Page 84 - Accounting; Accounting records; The results of accounting record searches can be incorrect if
84 Chapter 3 Status and logging NN46110-602 02.01 In normal operation and routine troubleshooting, you need not examine many of these windows. Some of the information, such as routing information, is also available through other areas, such as System , Routing. Accounting The accounting log provides...
Page 85 - RADIUS accounting; Accounting. The VPN Router creates a file for each day and keeps the; Data collection task; The VPN Router does not sort accounting records and displays
Chapter 3 Status and logging 85 Nortel VPN Router Troubleshooting — Server The data collection system stores records in text-based files stored in the system/dclog subdirectory. The system stores the most recent 60 days of data. The system stores daily files, summary files, and summary history files...
Page 86 - “Field IDs for data collection records” on page 86
86 Chapter 3 Status and logging NN46110-602 02.01 • Summary file, summary.dc, with exactly five records that contain summary data. These values give historical graphs and reports about specific values. • Summary history file that contains records representing cumulative daily data for the most recen...
Page 87 - Logs; Event log
Chapter 3 Status and logging 87 Nortel VPN Router Troubleshooting — Server Logs The VPN Router uses several logs that provide different levels of information. The router stores the logs in text files, and the logs indicate what happened, when the event occurred, and the IP address and user ID of the...
Page 89 - Refresh; System log; “Event log” on page 87; Security log
Chapter 3 Status and logging 89 Nortel VPN Router Troubleshooting — Server 17 Click Refresh to display new log entries. 18 Click Reverse Chronological Order to log in reverse chronological order. System log The system log contains all system events that are significant enough to write to disk, inclu...
Page 90 - Configuration log
90 Chapter 3 Status and logging NN46110-602 02.01 • encryption, authentication, or compression • hours of access • number of session violations • communications with servers • LDAP • Remote Authentication Dial-In User Service (RADIUS) Configuration log The Configuration log records all configuration...
Page 92 - Accessing the diskette drive
92 Chapter 4 Emergency recovery NN46110-602 02.01 Accessing the diskette drive If the VPN Router has a front cover, you must remove it to gain access to the diskette drive. For more information about how to remove the front cover, see the installation guide. Starting the VPN Router with the recovery...
Page 93 - Starting from a recovery diskette; Reset; Using recovery on a diskless system; REC
Chapter 4 Emergency recovery 93 Nortel VPN Router Troubleshooting — Server Starting from a recovery diskette Start the router from a recovery diskette to restore the software image and file system to the hard drive of the VPN Router. 1 Remove the front cover. 2 Insert the recovery diskette into the ...
Page 94 - Restoring factory defaults or a backup configuration; either ide0
94 Chapter 4 Emergency recovery NN46110-602 02.01 Restoring factory defaults or a backup configuration Restore the factory default configuration if you lose the administrator password. 1 Start with the recovery diskette. 2 To restore the factory default configuration or the backup configuration, sel...
Page 95 - Reformatting the hard disk; Reformat
Chapter 4 Emergency recovery 95 Nortel VPN Router Troubleshooting — Server You can use the serial number to differentiate backup configurations from multiple VPN Routers that save on the same backup server. The serial number uniquely identifies the backup data of each router. If you did not configur...
Page 97 - Navigating the file system from the recovery diskette
Chapter 4 Emergency recovery 97 Nortel VPN Router Troubleshooting — Server Navigating the file system from the recovery diskette Use the File System Maintenance screen to navigate through the switch file system. The top level lists the devices (drives) and lists the directories beneath a drive. Use ...
Page 98 - For some reason, the NVR configuration is lost.
98 Chapter 4 Emergency recovery NN46110-602 02.01 The unit is upgraded to the latest 8.0 build, configurations are preserved and the upgrade is successful. 3 You must again save the LDAP and config files on this new software version as you cannot restore the LDAP and config files from a previous ver...
Page 99 - “Introduction” on page 99; connectivity
99 Nortel VPN Router Troubleshooting — Server Chapter 5Troubleshooting This chapter introduces the concepts and practices of advanced network configuration and troubleshooting for the Nortel VPN Router. Use this chapter when you establish or modify the extranet, and when you diagnose network problem...
Page 100 - Nortel VPN Router Troubleshooting —; Troubleshoot connectivity problems; Modem and dial-up problems; “I cannot browse the Web or check my e-mail over my dial-up connection.”; Extranet connection problems
100 Chapter 5 Troubleshooting NN46110-602 02.01 Troubleshooting remote access problems typically starts at the client end when the remote user cannot establish a connection, loses a connection, cannot browse the network, or print. When connectivity problems occur and the source of the problem is unk...
Page 101 - Problems with name resolution using DNS services; Client connection problems
Chapter 5 Troubleshooting 101 Nortel VPN Router Troubleshooting — Server Problems with name resolution using DNS services “I logged into my corporate network, but I get messages saying the host is unknown.” “I can ping the host using its IP address, but not using its host name.” Network browsing pro...
Page 102 - Serial PPP problems; I connected a modem, but I cannot form a PPP connection.
102 Chapter 5 Troubleshooting NN46110-602 02.01 Serial PPP problems You use Serial Point-to-Point Protocol (PPP) to manage the VPN Router from a remote location using PPP and the serial interface. If the VPN Router becomes unreachable over the Internet, you can still dial up and manage it through th...
Page 103 - Settings) and restart the VPN Router. To use the Serial Menu,
Chapter 5 Troubleshooting 103 Nortel VPN Router Troubleshooting — Server To manage the VPN Router, disconnect the dial-up connection and try to reestablish it. This gives the modem a chance to renegotiate the baud rate with the VPN Router. Cause: You configure the port to use PPP but you want to use...
Page 104 - SFTP connection problems; Branch office connection problems; Cause
104 Chapter 5 Troubleshooting NN46110-602 02.01 SFTP connection problems If you cannot connect to the VPN Router using the SFTP, ensure that SSH works properly. In Global Configuration mode, view the SSH from CLI using the show ssh-server state command or from the GUI by choosing Servers, SSH. Resta...
Page 105 - Open a command prompt and ping the host with a fully qualified host; Network browsing problems; Cannot browse the network (with NetBEUI)
Chapter 5 Troubleshooting 105 Nortel VPN Router Troubleshooting — Server Action: Open a command prompt and ping the host with a fully qualified host name (for example, www.nortel.com). If you receive a response, verify that the IP address returned on the first line (for example, www.nortel.com [207....
Page 106 - A Windows Internet Name Service (WINS) server is not configured for
106 Chapter 5 Troubleshooting NN46110-602 02.01 Cannot access network shares after establishing an extranet access connection Cause: A Windows Internet Name Service (WINS) server is not configured for PPTP or IPsec connections on the VPN Router. Action: Verify that the Nortel VPN Client uses a WINS ...
Page 107 - Diagnosing WAN link problems; HDLC framing
Chapter 5 Troubleshooting 107 Nortel VPN Router Troubleshooting — Server Diagnosing WAN link problems WAN link problems can occur between the VPN Router and the public data network (PDN) at three levels: 1 T1/V.35 interface 2 HDLC framing 3 PPP layer If a connectivity problem occurs with the WAN lin...
Page 108 - Manager; Checking the HDLC framing; Manager WAN statistics; Check the PPP layer
108 Chapter 5 Troubleshooting NN46110-602 02.01 CSU/DSU is configured to use internal clocking, and that NRZ is encoded with CCITT CRC for the checksum. 3 Make sure that all the control signals assert (CTS, DCD, DSR, RTS, and DTR). You can check these signals on the VPN Router from the Manager WAN S...
Page 109 - while you view the WAN statistics window. If the state is; Hardware encryption accelerator connectivity; Troubleshoot performance problems; “Eliminating modem errors” on page 109; Eliminating modem errors
Chapter 5 Troubleshooting 109 Nortel VPN Router Troubleshooting — Server 1 Check whether the state of the PPP connection changes by periodically clicking Refresh while you view the WAN statistics window. If the state is always Down, PPP does not know that the link is up. If the state toggles between...
Page 110 - Performance tips for configuring Microsoft networking; DHCP Server assigns IP addresses to clients
110 Chapter 5 Troubleshooting NN46110-602 02.01 • Adjust the modem speed—If the speed of the modem is too high, it can cause hardware overruns. Reset the modem speed to match the real speed of the modem. • Disable hardware compression—The data passed through the extranet connection is encrypted, and...
Page 111 - What do I need to configure on the PPTP or IPsec client?; Dial; What is the preferred way to access neighbors on the network?; . If you experience delays using Network; Why are WINS settings different for extranet access?
Chapter 5 Troubleshooting 111 Nortel VPN Router Troubleshooting — Server What do I need to configure on the PPTP or IPsec client? The client needs the protocols for NetBIOS and TCP/IP configured. NetBEUI is not normally configured. Configure a Windows 2000 or Windows XP or Vista client so that it ex...
Page 112 - What WINS settings does Nortel recommend?; Configuration
112 Chapter 5 Troubleshooting NN46110-602 02.01 What WINS settings does Nortel recommend? Use the Start menu , Programs , Administrator Tools to configure the WINS settings on the WINS server. The values for a WINS server are • Server Configuration • Renewal Interval: 41 minutes • Extinction Interva...
Page 113 - What can I try on the WINS server if it does not work?; Can I control which machine is the master browser?
Chapter 5 Troubleshooting 113 Nortel VPN Router Troubleshooting — Server What can I try on the WINS server if it does not work? You can request a cleanup of the WINS server database by choosing Mappings, Initiate Scavenging. If the database becomes very large, you can compact it by using the jetpack...
Page 114 - Why are subnet masks important?
114 Chapter 5 Troubleshooting NN46110-602 02.01 The registry parameter IsDomainMasterBrowser impacts which servers become master browsers and backup browsers. The registry path for this parameter is \HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Browse r\ Parameters. Setting the IsDomainMaste...
Page 115 - What must I do about subnets?
Chapter 5 Troubleshooting 115 Nortel VPN Router Troubleshooting — Server If all hosts that the client tries to reach lie on the same physical segment, the contact fails. This failure is because every host on the physical network receives all the subnets broadcast and probably responds, if appropriat...
Page 116 - Why can I not browse another client in a different tunnel?; If you do not use a WINS server, this action is not possible because
116 Chapter 5 Troubleshooting NN46110-602 02.01 The outcome is somewhat different for IPsec and PPTP. For IPsec, the client recognizes this incorrect behavior and refuses to even send the packets. You can see a counter of the number of invalid packets of this type on the client under the status Inva...
Page 117 - “Additional information” on page 119
Chapter 5 Troubleshooting 117 Nortel VPN Router Troubleshooting — Server Where can I get more information about configuring PPTP on my client? Many articles exist in the Microsoft Knowledge Base about how to configure PPTP for Windows NT, Windows 2000, and Windows XP. For more information, see “Addi...
Page 118 - The Microsoft Windows 2000 or Windows XP and Windows NT; on Windows NT or; on Windows 2000 or Windows XP.
118 Chapter 5 Troubleshooting NN46110-602 02.01 For Windows 2000 or XP, and Windows NT, after a host name translates to an IP address (for example, to browse the Web or use e-mail), the host queries all DNS servers. The first server to respond with an IP address provides the information to the host....
Page 119 - Additional information; Troubleshoot general problems; “Web browser problems and the Nortel VPN Client Manager” on page 120
Chapter 5 Troubleshooting 119 Nortel VPN Router Troubleshooting — Server Action: You can wait for the socket to time out, but it is often more expedient to reboot. On Windows NT a similar problem occurs, but the cause is a TCP checksum error generated by the Microsoft IP stack. The only current reso...
Page 120 - “Reporting a problem with a Web browser” on page 124; Web browser problems and the Nortel VPN Client Manager; Display setting; Enabling Web browser options; Tools; and then select one of the following options:
120 Chapter 5 Troubleshooting NN46110-602 02.01 • “Reporting a problem with a Web browser” on page 124 • “System problems” on page 124 • “Solving routing problems” on page 126 • “Solving firewall problems” on page 129 • “Diagnosing LDAP problems” on page 132 Web browser problems and the Nortel VPN C...
Page 121 - Edit; , and then select one of the following options:; Long delays when Web browsing; HTTP—Sometimes when you use HTTP to connect to the Web interface,; Improving performance with Internet Explorer 4.0
Chapter 5 Troubleshooting 121 Nortel VPN Router Troubleshooting — Server • Run ActiveX scripts—If you disable this option, navigational titles do not update, and the Logoff and Help buttons do not work. • Enable Java programs—If you disable this option, navigational menus do not appear. Verify that ...
Page 122 - manually clear the browser cache in Netscape V4.x, select; Web browser error messages; No data in post message; To see the window, use the left navigational area to select it.; Internal error message; VPN Router is very low on memory.; Document not found message
122 Chapter 5 Troubleshooting NN46110-602 02.01 can clear the browser cache, which causes the browser to request all windows the next time you try to access them. To manually clear the browser cache in Internet Explorer V4.x, select Tools , Internet Options , and then click Delete Files . To manuall...
Page 123 - New administrator logon ignored
Chapter 5 Troubleshooting 123 Nortel VPN Router Troubleshooting — Server New administrator logon ignored Cause: Internet Explorer saves the user ID and password in its cache and automatically resends those values on subsequent logon attempts. Therefore, after an idle timeout, the browser ignores the...
Page 124 - Reporting a problem with a Web browser; Excessive active sessions logged
124 Chapter 5 Troubleshooting NN46110-602 02.01 Action: To avoid this situation, increase the color display setting to 256 or greater. Check with the video card manufacturer documentation to confirm that the video card supports 256 colors or greater. Reporting a problem with a Web browser When you r...
Page 125 - Group and user profile settings not saved
Chapter 5 Troubleshooting 125 Nortel VPN Router Troubleshooting — Server Cannot convert from an internal address pool to an external DHCP server Cause: You cannot convert IP address distribution from an internal address pool to an external DHCP server while sessions are active. Action: Select Admin,...
Page 126 - Solving routing problems; The following sections describe routing problems.; Routing
126 Chapter 5 Troubleshooting NN46110-602 02.01 Solving routing problems The following sections describe routing problems. The number of current Utunnel host users can display more than the configured maximum. Cause: This message is not an error and indicates the running state of the system. For exa...
Page 127 - The client machine receives ICMP redirect messages.; commands
Chapter 5 Troubleshooting 127 Nortel VPN Router Troubleshooting — Server The routing table cannot be altered after the Extranet Connection has been established.... The Extranet Connection has been Closed Cause: This error message appears on the client machine after the routing table changes on the c...
Page 128 - Cannot enable IGMP Global; No multicast data traffic passes; No IGMP control traffic flows towards or from downstream
128 Chapter 5 Troubleshooting NN46110-602 02.01 If you cannot determine the cause for the routing update, consider using mandatory tunneling for the users with problems; avoid using split tunneling for these users. If none of these methods solve the problem, contact Global Nortel Technical Support (...
Page 129 - Solving firewall problems; An error occurred while parsing the policy
Chapter 5 Troubleshooting 129 Nortel VPN Router Troubleshooting — Server Action: The VPN Router posts the alert No downstream interface is up to the Status, Health Check window. IGMP needs exactly one downstream interface with IGMP enabled. Try to bring the downstream interface back online. If no do...
Page 130 - Unable to communicate with the VPN Router
130 Chapter 5 Troubleshooting NN46110-602 02.01 3 Check that the connection to the VPN Router established. 4 Restart the browser and browse to the Services, Firewall/NAT window. 5 Reload the Stateful Firewall Manager . Authorization failed. Please try again. Cause: This error occurs after you provid...
Page 131 - System files were not loaded properly
Chapter 5 Troubleshooting 131 Nortel VPN Router Troubleshooting — Server • The port or IP address of the external LDAP server changes. Action: To ensure that the most current data is loaded, perform the following activities: 1 Close the current policy, if opened. You cannot save until you fix this e...
Page 132 - Restart the browser and browse to the; Services; Reload the; Stateful Firewall Manager; Diagnosing LDAP problems; Admin; command. This command lists all the ports the
132 Chapter 5 Troubleshooting NN46110-602 02.01 7 Restart the browser and browse to the Services , Firewall/NAT window. 8 Reload the Stateful Firewall Manager . Diagnosing LDAP problems Use the event log and traffic captures to troubleshoot problems that can arise when you configure the VPN Router t...
Page 136 - Certificate messages; Manually delete all files in the; Nortel manufactures the VPN Router with trusted CA certificates; tCert: Shutdown complete
136 Troubleshooting system messages NN46110-602 02.01 Certificate messages Error removing CA certificate file: xxx Description: Nortel manufactures VPN Router with a trusted certificate authority (CA) certificate for use by Secure Sockets Layer (SSL). The first time that you start the router, it rem...
Page 137 - tCert: X.509 certificates disabled in flash memory; ISAKMP messages; ISAKMP
Troubleshooting system messages 137 Nortel VPN Router Troubleshooting — Server tCert: X.509 certificates disabled in flash memory Description: This message is an informational message that indicates the use of X.509 certificates by the VPN Router is disabled. Action: No action required. Warning: Sys...
Page 142 - This message indicates a mismatch in the Diffie-Hellman; IPsec messages; Authentication failure detected--npbuf 0x009d7c60; An authentication failure occurs on the hardware accelerator.
142 Troubleshooting system messages NN46110-602 02.01 Diffie-Hellman group mismatch for a.b.c.d—terminating connection attempt Description: This message indicates a mismatch in the Diffie-Hellman configuration. Action: Configure the Diffie-Hellman group profiles (Profiles, Branch Office, Group Confi...
Page 143 - Inbound ESP from; Branch office messages; Couldn't install route for
Troubleshooting system messages 143 Nortel VPN Router Troubleshooting — Server Unable to send ESPUDP data, destination UDP port unknown— packet dropped Description: The destination User Datagram Protocol (UDP) port is 0; therefore the router drops the Encapsulating Security Payload (ESP) packet. Act...
Page 144 - Using RFC 3947 NAT traversal
144 Troubleshooting system messages NN46110-602 02.01 Action: No action is required. Secondary authentication failed for session %s[%.*s]:%d Description: The secondary authentication for the branch office tunnel fails. The user name and password you configure locally or externally for two factor aut...
Page 145 - IPSec NAT traversal disabled in system; User tunnel messages
Troubleshooting system messages 145 Nortel VPN Router Troubleshooting — Server NAT NOT detected. Local address a.b.c.d:x, remote address a.b.c.d:x Description: The router does not detect NAT between the peers. Action: No action is required. NAT detected. Local address a.b.c.d:x, remote address a.b.c...
Page 146 - SSL messages; Child cert
146 Troubleshooting system messages NN46110-602 02.01 Action: Verify the user name and password. SSL messages Checking chain: invalid parent cert, xxx Description: The certificate in the chain is not valid. This message indicates that the certificate installed at the external LDAP server expired or ...
Page 147 - trusted on the VPN Router.; Database messages; Reinstall the VPN Router software.; Restore the VPN Router software from a File Transfer Protocol (FTP)
Troubleshooting system messages 147 Nortel VPN Router Troubleshooting — Server No matching trusted CA certs Description: None of the certificates in the chain are trusted CA certificates. This message appears if you did not install the CA certificate or if it is not marked as trusted on the VPN Rout...
Page 148 - could not back up; Security messages; uid; not found in account
148 Troubleshooting system messages NN46110-602 02.01 LDIF file: xxx could not back up Description: The internal LDAP server database cannot back up to the specified LDIF file. This error can occur if the name of the LDIF file is not in 8.3 format. Action: Make sure the backup file uses an 8.3 file ...
Page 152 - SchemaCls: Database schema not available; The external LDAP server does not support a schema entry so it is; being referenced by; Another LDAP entry references the specific LDAP entry, for; uid invalid—authentication failed; The IPsec hashed user ID (UID) is not found in the LDAP database.; invalid uid—authentication failed; The group UID is not found in the LDAP database, or the UID is; session rejected—system is initializing; The VPN Router rejected an incoming request because it is still
152 Troubleshooting system messages NN46110-602 02.01 SchemaCls: Database schema not available Description: The external LDAP server does not support a schema entry so it is not possible to update the schema over the network. This error occurs if the external LDAP server does not support the cn=sche...
Page 153 - xxx—
Troubleshooting system messages 153 Nortel VPN Router Troubleshooting — Server Action: Wait to make sure that the VPN Router initializes, and then try again. Session: xxx[xxx] session rejected—system is shutting down Description: The VPN Router rejected an incoming request because it is shutting dow...
Page 154 - IP address assignment failed; L2TP host; account has max links; account has max sessions
154 Troubleshooting system messages NN46110-602 02.01 • The call admission priority slot is full. • The call admission priority slot is outside of access hours. • The maximum links configured for the group is reached. Action: Verify the correct settings for each of the possible causes. Session: xxx[...
Page 156 - connect Qos level
156 Troubleshooting system messages NN46110-602 02.01 Session: xxx[xxx] : xxx connect Qos level xxx full Description: No more slots are available for the call admission priority of the session. This indicates that the configured Call Admission Priority for the group to which the request is assigned ...
Page 159 - RADIUS accounting messages; RADIUS: Cannot send accounting request to <; port number
Troubleshooting system messages 159 Nortel VPN Router Troubleshooting — Server tEvtLgMgr 0 : Security [12] Session 15fc2c68: IPSEC[u440875]:90024 sib 0 logged out Description: This message shows that the session is removed from the account collection. For example, every branch office uses a session ...
Page 160 - error; Indicated packet length too large
160 Troubleshooting system messages NN46110-602 02.01 RADIUS: < server-name > server timed out Description: This message indicates a connection failure. The connection timed out while waiting for a response. Action: Verify the following information: • RADIUS server IP address and port number •...
Page 161 - > accounting record to; number; Received bad attribute type from server; The RADIUS attribute value is incorrect.; Response OK; This message indicates that the router receives a valid response.
Troubleshooting system messages 161 Nortel VPN Router Troubleshooting — Server RADIUS: failure sending < user-name > accounting record to < server-name > Description: This message indicates that the router receives an invalid response. The length of the response packet is not equal to th...
Page 162 - > accounting record sent to; RADIUS authentication messages; to DNS translation failure
162 Troubleshooting system messages NN46110-602 02.01 RADIUS: < user-name > accounting record sent to < server-name > OK Description: This message indicates that the router receives a valid response. Action: No action necessary. RADIUS authentication messages RADIUS: Cannot send request ...
Page 163 - port; > server timed out authenticating; > server error while authenticating
Troubleshooting system messages 163 Nortel VPN Router Troubleshooting — Server RADIUS: no reply from RADIUS server < server-name >(< port number >) Description: This message indicates a connection failure. The connection timed out while waiting for a response. Action: Verify the followin...
Page 166 - RADIUS access challenge received; The Nortel VPN Client receives this message. The client receives a; RADIUS server rejected access
166 Troubleshooting system messages NN46110-602 02.01 RADIUS access challenge received Description: The Nortel VPN Client receives this message. The client receives a valid access-challenge response. Action: No action required. RADIUS server rejected access Description: This message indicates that t...
Page 167 - Routing messages; Unable to create; for OSPF
Troubleshooting system messages 167 Nortel VPN Router Troubleshooting — Server Routing messages Unable to create xxx for OSPF Description: The VPN Router cannot create the necessary components to initialize OSPF. This happens if the VPN Router runs out of free memory. Action: Choose Routing, OSPF. D...
Page 168 - OSPF Enabled
168 Troubleshooting system messages NN46110-602 02.01 OSPF Enabled Description: The administrator enabled OSPF from the Routing , OSPF window. Action: No action required. Ospf_Global.State changed from DISABLED to Enabled by user 'admin' @ a.b.c.d Description: The administrator disabled OSPF from th...
Page 173 - mask
Troubleshooting system messages 173 Nortel VPN Router Troubleshooting — Server IP Redirector [11] FEM DynRoutingAddrReg: ip a.b.c.d mask x.x.x.x deleting old rt 0x35d4ca84 flags 0x500003 pr 13 prio 4 Description: The routing table includes a route, for example route a.b.c.d , obtained through route ...
Page 174 - PPP messages
174 Troubleshooting system messages NN46110-602 02.01 RSVP [06] AddRsvpSource for dst 0xa78327c2, srcport 0 rate 3500 bkt 3000 Description: This message is an informational message. The address is modified to appear in IP form. Action: No action is required. PPP messages Ppp0x04ade338 [06] SimpleDeF...
Page 175 - control packet was transmitted.; Hardware messages; This message indicates that the configuration file contains an; nnn
Troubleshooting system messages 175 Nortel VPN Router Troubleshooting — Server 582256 10/07/2007 19:37:17 (Ppp0x04d45) INFO IO WANPPP Code 44 packetLogArea Note: The above event repeated xx time(s) Description: This message is an informational message that indicates that a PPP control packet was tra...
Page 176 - ERR ADSL Slot 3 Interface 1 on line (microcode loaded)
176 Troubleshooting system messages NN46110-602 02.01 Action: No action required. HWAccel [ nnn ] not present, deleting from config Description: This indicates the configuration file contains a HWAccel [nnn] entry, but no hardware accelerator exists in the slot. The HWAccel [nnn] entry is deleted fr...
Page 177 - the number in this message. If the numbers do not match, contact GNTS.; Management messages; Ethernet [02] Unable to deactivate circuit mapping; the circuit mapping for the management interface.
Troubleshooting system messages 177 Nortel VPN Router Troubleshooting — Server Action: Physically verify that the number of accelerators in the system matches the number in this message. If the numbers do not match, contact GNTS. Hw Accel unit [03] ppDatap = 0 0x934ec2 npbufStart =0x934d60, getRsltE...
Page 178 - DNS messages; This message indicates a DNS Proxy datagram was destined for a
178 Troubleshooting system messages NN46110-602 02.01 Action: Select a server certificate for HTTPS authentication from Services, SSL TLS. DNS messages DNS_PROXY [14] Listener: new datagram Description: This message indicates a DNS Proxy datagram was destined for a private interface address. Prior t...
Page 179 - Novell IPX MIB; The VPN Router supports the IPX MIB distributed by Novell, Inc.
179 Nortel VPN Router Troubleshooting — Server Appendix AMIB support The VPN Router supports the management information base (MIB) for use with network management protocols in TCP/IP (Transmission Control Protocol over IP)-based Internets and TCP/IPX-based networks. The VPN Router supports SNMP (Sim...
Page 180 - The VPN Router supports RFC 1213,; RFC 1724—RIP Version 2 MIB Extension; The VPN Router supports RFC 1724,
180 Appendix A MIB support NN46110-602 02.01 RFC 1213—Network Management of TCP/IP-Based Internets MIB The VPN Router supports RFC 1213, Management Information Base for Network Management of TCP/IP-based Internets: MIB II . This RFC provides the architecture and system for managing TCP/IP-based inte...
Page 181 - RFC 1850—OSPF Version 2 Management Information Base; The VPN Router supports RFC 1850,; RFC 2571—Snmp-Framework MIB; The VPN Router supports RFC 2667,
Appendix A MIB support 181 Nortel VPN Router Troubleshooting — Server RFC 1850—OSPF Version 2 Management Information Base The VPN Router supports RFC 1850, OSPF Version 2 Management Information Base . As stated in the introduction to the RFC, the RFC “defines a portion of the Management Information ...
Page 182 - The VPN Router supports RFC 2787,
182 Appendix A MIB support NN46110-602 02.01 RFC 2737—Entity MIB This MIB contains five tables two of which are partially implemented. *entPhysicalTable entLogicalTable entLPMappingTable *entAliasMappingTable entPhysicalContainsTable The entPhysicalTable provides a list of the hardware elements that...
Page 183 - RFC2790—Host Resources MIB
Appendix A MIB support 183 Nortel VPN Router Troubleshooting — Server RFC2790—Host Resources MIB The Host Resources MIB defines a uniform set of objects for the managing host computers. Host computers are independent of the operating system, network services, or software application. The Host Resour...
Page 184 - RFC 2863—Interface MIB (64 bit counters support)
184 Appendix A MIB support NN46110-602 02.01 hrSWRunPerf • hrSWRunTable — hrSWRunIndex — hrSWRunName — hrSWRunType — hrSWRunStatus — hrSWRunPriority • hrSWRunPerfTable — hrSWRunPerfCPU RFC 2863—Interface MIB (64 bit counters support) The interface table adds support for the following entries: ifHCIn...
Page 185 - The objects and their parameters(indices) are; VPN Router MIB provides trap acknowledgement.
Appendix A MIB support 185 Nortel VPN Router Troubleshooting — Server sends five pings. One ping is sent by itself so that if the device you ping is the other end of a branch office tunnel, it ensures that the tunnel is brought up before trying to send pings through the tunnel. This ping is not coun...
Page 186 - cestraps.mib—Nortel proprietary MIB
186 Appendix A MIB support NN46110-602 02.01 cestraps.mib—Nortel proprietary MIB This section lists the contents of the cestraps.mib, the Nortel MIB for the VPN Router. -- Trap #5005 --------------------------------- -- Each Trap contains the Trap OID as well as the following OIDs: -- SeverityLevel ...
Page 188 - newoak
188 Appendix A MIB support NN46110-602 02.01 newoak.mib This section provides the contents of the newoak.mib, which defines the newoak enterprise ID, the contivity object identifier, and the sysObjectIDs for each VPN Router model. -- This MIB module uses the extended OBJECT-TYPE macro as -- defined ...
Page 190 - Hardware-related traps
190 Appendix A MIB support NN46110-602 02.01 Hardware-related traps hardwareTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 1} -- Trap #1001 hardDisk1Status OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Hard Disk Number 1 Status." ::= {hardwareTrapInfo 1}...
Page 196 - Software-related traps
196 Appendix A MIB support NN46110-602 02.01 SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of Certificates Validity." ::= {serverCESTrapInfo 11} Software-related traps softwareTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 3} -- Trap #5001 NetBuffers OBJECT-T...
Page 197 - Intrusion-related traps
Appendix A MIB support 197 Nortel VPN Router Troubleshooting — Server Intrusion-related traps intrusionTrapInfo OBJECT IDENTIFIER ::= {ContivitySnmpTraps 5} -- Trap #201 securityIntrusion OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Login Security Intrusion....
Page 198 - Information passed with every trap
198 Appendix A MIB support NN46110-602 02.01 Information passed with every trap SeverityLevel OBJECT-TYPE SYNTAX INTEGER { fatal(1), major(2), minor(3), informational(4), insignificant(5), reversal(6) } ACCESS read-only STATUS mandatory DESCRIPTION "Severity of specific trap." ::= {Contivity...
Page 199 - “Trap categories” on page 199
Appendix A MIB support 199 Nortel VPN Router Troubleshooting — Server Table 15 “Trap categories” on page 199 provides trap categories. Table 15 Trap categories Hardware 1.3.6.1.4.1.2505.1.1.0.1001 hardDisk1StatusTrap 1.3.6.1.4.1.2505.1.1.0.1002 hardDisk0StatusTrap 1.3.6.1.4.1.2505.1.1.0.1003 memoryU...
Page 221 - Index
Nortel VPN Router Troubleshooting — Server 221 Index A accounting data 86records 84, 85 accounting log 84 active sessions 124 ActiveX Scripts 120 B background images 123 branch office error messages 143 browser error messages 122 browsing delays 121 C certificate error messages 136 cestraps.mib 186 ...