ZyXEL Communications ZyWALL 110 Handbook page 310

Security firewalls zywall/usg series
Hide thumbs Also See for ZyWALL 110:
Table of Contents

Advertisement

2. If you see [info] or [error] log message such as below, please check ZyWALL/USG
Phase 1 Settings. iOS users must use the same Pre-Shared Key as configured in
ZyWALL/USG to establish the IKE SA.
3. If you see that Phase 1 IKE SA process has completed but still get [info] log message
as below, please check ZyWALL/USG Phase 2 Settings. ZyWALL/USG unit must set
correct Local Policy to establish the IKE SA.
4. Ensure that the L2TP Address Pool does not conflict with any existing LAN1, LAN2,
DMZ, or WLAN zones, even if they are not in use.
5. If you cannot access devices in the local network, verify that the devices in the
local network set the USG's IP as their default gateway to utilize the L2TP tunnel.
6. Make sure the ZyWALL/USG units' security policies allow IPSec VPN traffic. IKE uses
UDP port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
7. Verify that the Zone is set correctly in the VPN Connection rule. This should be set to
IPSec_VPN Zone so that security policies are applied properly.
www.zyxel.com
310/749

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents