Zyxel ZyWALL 1100 [235/327] What could go wrong

Zyxel USG 60 [235/327] What could go wrong
Chapter 5 Create Client-to-Site VPN Tunnels
ZyWALL/USG Series Handbook
235
4 Go to Android mobile device Menu > Settings > Wireless & Networks > VPN and verify the
connection status.
Figure 505 Menu > Settings > Wireless & Networks > VPN
5.2.4 What Could Go Wrong?
1 If you see [alert] log message such as below, please check ZyWALL/USG L2TP Allowed User or
User/Group Settings. Android Mobile users must use the same Username and Password as
configured in ZyWALL/USG to establish the L2TP VPN.
Figure 506 MONITOR> Log
2 If you see [info] or [error] log message such as below, please check ZyWALL/USG Phase 1 Settings.
Android Mobile users must use the same Secret as configured in ZyWALL/USG to establish the IKE
SA.
Figure 507 MONITOR> Log
3 If you see that Phase 1 IKE SA process has completed but still get [info] log message as below,
please check ZyWALL/USG Phase 2 Settings. ZyWALL/USG unit must set correct Local Policy to
establish the IKE SA.
Figure 508 MONITOR> Log
4 Ensure that the L2TP Address Pool does not conflict with any existing LAN1, LAN2, DMZ, or WLAN
zones, even if they are not in use.
5 If you cannot access devices in the local network, verify that the devices in the local network set
the USG’s IP as their default gateway to utilize the L2TP tunnel.
6 Make sure the ZyWALL/USG units’ security policies allow IPSec VPN traffic. IKE uses UDP port 500,
AH uses IP protocol 51, and ESP uses IP protocol 50.
7 Verify that the Zone is set correctly in the Zone object. This should be set to IPSec_VPN Zone so
that security policies are applied properly.

Содержание

Похожие устройства