Zyxel ZyWALL 1100 [144/327] What could go wrong

Zyxel ZyWALL 110 [144/327] What could go wrong
Chapter 4 Create Site-to-Site VPN Tunnels
ZyWALL/USG Series Handbook
144
4.4.4 What Could Go Wrong?
1 If you see below [info] or [error] log message, please check ZyWALL/USG Phase 1 Settings. Both
ZyWALL/USG and Cisco must use the same Pre-Shared Key, Encryption, Authentication method, DH
key group and ID Type to establish the IKE SA.
Figure 299 MONITOR > Log
2 If you see that Phase 1 IKE SA process done but still get below [info] log message, please check
ZyWALL/USG and Cisco Phase 2 Settings. Both ZyWALL/USG and Cisco must use the same
Protocol, Encapsulation, Encryption, Authentication method and PFS to establish the IKE SA.
Figure 300 MONITOR > Log
3 Make sure the both ZyWALL/USG and Cisco security policies allow IPSec VPN traffic. IKE uses UDP
port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
4 Default NAT traversal is enable on ZyWALL/USG, please make sure the remote IPSec device must
also have NAT traversal enabled.
4.5 How to Configure Site-to-site IPSec VPN with
WatchGuard
This example shows how to use the VPN Setup Wizard to create a site-to-site VPN between a
ZYWALL/USG and a WatchGuard router. The example instructs how to configure the VPN tunnel
between each site. When the VPN tunnel is configured, each site can be accessed securely.
Figure 301 ZyWALL Site-to-site IPSec VPN with WatchGuard Connected

Содержание

Похожие устройства