ZyXEL Communications ZyWALL 110 Handbook page 335

Security firewalls zywall/usg series
Hide thumbs Also See for ZyWALL 110:
Table of Contents

Advertisement

www.zyxel.com
If you see that Phase 1 IKE SA process has completed but still get [info] log
message as below, please check ZyWALL/USG Phase 2 Settings. ZyWALL/USG unit
must set correct Local Policy to establish the IKE SA.
Ensure that the L2TP Address Pool does not conflict with any existing LAN1, LAN2,
DMZ, or WLAN zones, even if they are not in use.
If you cannot access devices in the local network, verify that the devices in the
local network set the USG's IP as their default gateway to utilize the L2TP tunnel.
Make sure the ZyWALL/USG units' security policies allow IPSec VPN traffic. IKE uses
UDP port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
Verify that the Zone is set correctly in the Zone object. This should be set to
IPSec_VPN Zone so that security policies are applied properly.
335/749

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents