ZyXEL Communications ZyWall USG 2000 User Manual page 800

Unified security gateway
Hide thumbs Also See for ZyWall USG 2000:
Table of Contents

Advertisement

Chapter 52 Troubleshooting
• The ZyWALL supports UDP port 500 and UDP port 4500 for NAT traversal. If you
enable this, make sure the To-ZyWALL firewall rules allow UDP port 4500 too.
• Make sure regular firewall rules allow traffic between the VPN tunnel and the
rest of the network. Regular firewall rules check packets the ZyWALL sends
before the ZyWALL encrypts them and check packets the ZyWALL receives after
the ZyWALL decrypts them. This depends on the zone to which you assign the
VPN tunnel and the zone from which and to which traffic may be routed.
• If you set up a VPN tunnel across the Internet, make sure your ISP supports AH
or ESP (whichever you are using).
• If you have the ZyWALL and remote IPSec router use certificates to
authenticate each other, make sure they trust each other's certificates. If the
ZyWALL's certificate is self-signed, import it into the remote IPsec router. If it is
signed by a CA, make sure the remote IPsec router trusts that CA. The ZyWALL
uses one of its Trusted Certificates to authenticate the remote IPSec router's
certificate. The trusted certificate can be the remote IPSec router's self-signed
certificate or that of a trusted CA that signed the remote IPSec router's
certificate.
I cannot set up an L2TP VPN tunnel.
Make sure you have configured L2TP correctly on the remote user computers. See
1
Section 28.6 on page 418
Make sure you configured an appropriate policy route on the ZyWALL.
2
Make sure there is not a firewall or NAT router between the ZyWALL and the
3
remote users.
Make sure the remote users are using public IP addresses.
4
The VPN connection is up but VPN traffic cannot be transmitted through the VPN
tunnel.
Routing policies define how the ZyWALL forwards packets to their destinations.
You must create a policy route for the ZyWALL to route VPN traffic through a VPN
tunnel to the remote network.
The VPN wizard automatically creates a corresponding policy route. If you use the
VPN > IPSec VPN or VPN > L2TP VPN screens to set up a VPN tunnel, you
need to manually configure a policy route for the VPN tunnel.
800
for examples.
ZyWALL USG 2000 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents