John,
This is great - I can't thank you enough for your help.
Here's the output from your commands.
ns25-> get int tun.2
Interface tunnel.2:
description tunnel.2
number 20, if_info 4176, if_index 2, mode route
link ready
vsys Root, zone VPN Zone, vr trust-vr
admin mtu 1500, operating mtu 1500, default mtu 1500
*ip 0.0.0.0/0 unnumbered, source interface ethernet3
*manage ip 0.0.0.0
bound vpn:
Vodafone VPN
Next-Hop Tunnel Binding table
Flag Status Next-Hop(IP) tunnel-id VPN
pmtu-v4 disabled
ping disabled, telnet disabled, SSH disabled, SNMP disabled
web disabled, ident-reset disabled, SSL disabled
DNS Proxy disabled
RIP disabled RIPng disabled mtrace disabled
PIM: not configured IGMP not configured
bandwidth: physical 0kbps, configured egress [gbw 0kbps mbw 0kbps]
configured ingress mbw 0kbps, current bw 0kbps
total allocated gbw 0kbps
Number of SW session: 24010, hw sess err cnt 0
ns25-> get sa
total configured sa: 1
HEX ID Gateway Port Algorithm SPI Life:sec kb Sta PID vsys
00000020< 212.xxx.xxx.35 500 esp: des/md5 00000000 expir unlim I/I -1 0
00000020> 212.xxx.xxx.35 500 esp: des/md5 00000000 expir unlim I/I -1 0
ns25-> get event
Total event entries = 3070
Date Time Module Level Type Description
2007-12-20 22:46:07 system warn 00002 Cannot connect to e-mail server
192.168.1.10.
2007-12-20 22:41:46 system info 00536 IKE<212.xxx.xxx.35> Phase 1:
Retransmission limit has been reached.
2007-12-20 22:40:54 system info 00767 System configuration saved by user via
web from host 84.66.251.91 to
82.xxx.xxx.56:80 by user
2007-12-20 22:40:54 system notif 00018 Policy (46, Untrust->VPN Zone,
Vodafone Handset Range #1->Any,ANY,
Permit) was modified by user via web
from host 84.66.251.91 to
82.xxx.xxx.56:80
2007-12-20 22:40:54 system notif 00018 Policy (46, Untrust->VPN Zone,
Vodafone Handset Range #1->Any,ANY,
Permit) was modified by user via web
from host 84.66.251.91 to
82.xxx.xxx.56:80
2007-12-20 22:40:54 system notif 00018 Policy (46, Untrust->VPN Zone,
Vodafone Handset Range #1->Any,ANY,
Permit) was modified by user via web
ns25-> get ike cookie
Active: 0, Dead: 0, Total 0
ns25-> get db str
## 2007-12-20 22:49:22 : ms -465534289 rt-timer callback
## 2007-12-20 22:49:22 : ms -465534288 rt-timer callback
## 2007-12-20 22:49:23 : ms -465533289 rt-timer callback
## 2007-12-20 22:49:23 : ms -465533245 rt-timer callback
## 2007-12-20 22:49:24 : ms -465532289 rt-timer callback
## 2007-12-20 22:49:24 : ms -465532288 rt-timer callback
## 2007-12-20 22:49:25 : ms -465531289 rt-timer callback
## 2007-12-20 22:49:25 : ms -465531245 rt-timer callback
## 2007-12-20 22:49:26 : ms -465530289 rt-timer callback
## 2007-12-20 22:49:26 : ms -465530287 rt-timer callback
## 2007-12-20 22:49:27 : ms -465529289 rt-timer callback
## 2007-12-20 22:49:27 : ms -465529245 rt-timer callback
## 2007-12-20 22:49:27 : NHTB entry search no found: vpn none tif tunnel.2 nexthop 10.10.1.1
## 2007-12-20 22:49:27 : IKE<212.183.134.35> ****** Recv kernel msg IDX-0, TYPE-5 ******
## 2007-12-20 22:49:27 : IKE<212.183.134.35> ****** Recv kernel msg IDX-0, TYPE-5 ******
## 2007-12-20 22:49:27 : IKE<212.183.134.35> sa orig index<0>, peer_id<1>.
## 2007-12-20 22:49:27 : IKE<212.183.134.35> isadb get entry by peer/local ip and port
## 2007-12-20 22:49:27 : IKE<212.183.134.35> create sa: 82.108.195.56->212.183.134.35
## 2007-12-20 22:49:27 : getProfileFromP1Proposal->
## 2007-12-20 22:49:27 : find profile[0]=<00000001 00000001 00000001 00000001> for p1 proposal (id 20), xauth(0)
## 2007-12-20 22:49:27 : init p1sa, pidt = 0x0
## 2007-12-20 22:49:27 : change peer identity for p1 sa, pidt = 0x0