What Can Go Wrong - ZyXEL Communications ZyWALL 110 Handbook

Zywall/usg series security firewalls
Hide thumbs Also See for ZyWALL 110:
Table of Contents

Advertisement

Go to Android mobile device Menu > Settings > Wireless & Networks > VPN and verify the
4
connection status.
Figure 508 Menu > Settings > Wireless & Networks > VPN

5.2.4 What Can Go Wrong?

If you see [alert] log message such as below, please check ZyWALL/USG L2TP Allowed User or
1
User/Group Settings. Android Mobile users must use the same Username and Password as
configured in ZyWALL/USG to establish the L2TP VPN.
Figure 509
If you see [info] or [error] log message such as below, please check ZyWALL/USG Phase 1 Settings.
2
Android Mobile users must use the same Secret as configured in ZyWALL/USG to establish the IKE
SA.
Figure 510
If you see that Phase 1 IKE SA process has completed but still get [info] log message as below,
3
please check ZyWALL/USG Phase 2 Settings. ZyWALL/USG unit must set correct Local Policy to
establish the IKE SA.
Figure 511
Ensure that the L2TP Address Pool does not conflict with any existing LAN1, LAN2, DMZ, or WLAN
4
zones, even if they are not in use.
If you cannot access devices in the local network, verify that the devices in the local network set
5
the USG's IP as their default gateway to utilize the L2TP tunnel.
Make sure the ZyWALL/USG units' security policies allow IPSec VPN traffic. IKE uses UDP port 500,
6
AH uses IP protocol 51, and ESP uses IP protocol 50.
Chapter 5 Create Client-to-Site VPN Tunnels
ZyWALL/USG Series User's Guide
214

Advertisement

Table of Contents
loading

Table of Contents