Zyxel ZyWALL 1100 [153/327] What could go wrong

Zyxel ZyWALL 310 [153/327] What could go wrong
Chapter 4 Create Site-to-Site VPN Tunnels
ZyWALL/USG Series Handbook
153
4.5.4 What Could Go Wrong?
1 If you see below [info] or [error] log message, please check ZyWALL/USG Phase 1 Settings. Both
ZyWALL/USG and WatchGuard must use the same Pre-Shared Key, Encryption, Authentication
method, DH key group and ID Type to establish the IKE SA.
Figure 323 MONITOR > Log
2 If you see that Phase 1 IKE SA process done but still get below [info] log message, please check
ZyWALL/USG and WatchGuard Phase 2 Settings. Both ZyWALL/USG and WatchGuard must use the
same Protocol, Encapsulation, Encryption, Authentication method and PFS to establish the IKE SA.
Figure 324 MONITOR > Log
3 Make sure the both ZyWALL/USG and WatchGuard security policies allow IPSec VPN traffic. IKE
uses UDP port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
4 Default NAT traversal is enable on ZyWALL/USG, please make sure the remote IPSec device must
also have NAT traversal enabled.

Содержание

Похожие устройства