Zyxel USG 60 [133/327] What could go wrong

Zyxel USG 60 [133/327] What could go wrong
Chapter 4 Create Site-to-Site VPN Tunnels
ZyWALL/USG Series Handbook
133
3 Go to FortiGate VPN > Monitor > IPsec Monitor and check the tunnel Status is up and
Incoming Data/Outgoing Data traffic.
Figure 274 VPN > Monitor > IPsec Monitor
4 To test whether or not a tunnel is working, ping from a computer at one site to a computer at the
other. Ensure that both computers have Internet access (via the IPSec devices).
Figure 275 PC behind ZyWALL/USG > Window 7 > cmd > ping 192.168.2.33
Figure 276 PC behind FortiGate> Window 7 > cmd > ping 192.168.1.33
4.3.4 What Could Go Wrong?
1 If you see below [info] or [error] log message, please check ZyWALL/USG Phase 1 Settings. Both
ZyWALL/USG and FortiGate must use the same Pre-Shared Key, Encryption, Authentication
method, DH key group and ID Type to establish the IKE SA.
Figure 277 MONITOR > Log
2 If you see that Phase 1 IKE SA process done but still get below [info] log message, please check
ZyWALL/USG and FortiGate Phase 2 Settings. Both ZyWALL/USG and FortiGate must use the same
Protocol, Encapsulation, Encryption, Authentication method and PFS to establish the IKE SA.
Figure 278 MONITOR > Log

Содержание

Скачать