14.4 Communication Between Two Novell BorderManager 3.9 Slaves

PSK always takes precedence over certificate mode of authentication when two slaves are initiating connection between themselves.

This section gives the scenarios where Slave S1 and Slave S2 are communicating with each other:

Table 14-4 Communication Between Two Novell BorderManager 3.9 Slaves

Certificate

Auth method – Certificate

Slave S1(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder :IKE SA established to x.x.x.x

Certificate

Auth method – Certificate

Slave S2(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder : IKE SA established to x.x.x.x

PSK

Auth method – PSK

Certificate is also configured

Slave S1(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder :IKE SA established to x.x.x.x

Certificate

Auth method – Certificate

Slave S2(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder :IKE SA established to x.x.x.x

PSK

Auth method – PSKpsk = secretCertificate is also configured.Slave S1(3.9)Message : In csaudit logsInitiator : IKE SA established to x.x.x.xResponder : IKE SA establised to x.x.x.x

PSK

Auth method – PSK

psk = secret

Slave S2(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder : IKE SA established to x.x.x.x

Certificate

Auth method – Certificate

psk = secret

PSK is also configured

Slave S1(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder : IKE SA established to x.x.x.x

PSK

Auth method – PSK

psk = secret

Slave S2(3.9)

Message : In csaudit logs

Initiator : IKE SA established to x.x.x.x

Responder : IKE SA established to x.x.x.x

Certificate

Auth method – Certificate

psk = secret

PSK is also configured

Slave S1(3.9)

Message : In csaudit logs

Initiator : Pre-shared key mismatch in peer

Responder : Pre-shared key mismatch for peer x.x.x.x

PSK

Auth method – PSK

psk = secret1

Slave S2(3.9)

Message : In csaudit logs

Initiator : Pre-shared key mismatch in peer

Responder : Pre-shared key mismatch for peer x.x.x.x

Certificate

Auth method – Certificate

PSK is not configured

Slave S1(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured

Responder : NA

PSK

Auth method – PSK

Slave S2(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured in peer

Responder : NA

PSK

Auth method – PSK

Certificate is also configured.

Slave S1(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured in peer

Responder : NA

Certificate

Auth method – Certificate

PSK is not configured

Slave S2(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured

Responder : NA

PSK

Auth method – PSK

psk = secret

Certificate is also configured

Slave S1(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured in peer

Responder : Pre-shared key mismatch for peer x.x.x.x

Certificate

Auth method – Certificate

psk = secret1

PSK is configured with wrong secret

Slave S2(3.9)

Message : In csaudit logs

Initiator : Preshared key not configured in peer

Responder : Pre-shared key mismatch for peer x.x.x.x