ZyXEL Communications ZyWALL 110 Handbook & Instructions page 97

Hide thumbs Also See for ZyWALL 110:
Table of Contents

Advertisement

18
If you see that Phase 1 IKE SA process done but still get below [info] log message,
please check ZyWALL/USG Phase 2 Settings. Both ZyWALL/USG at the HQ and
Branch sites must use the same Protocol, Encapsulation, Encryption, Authentication
method and PFS to establish the IKE SA.
Figure 159 MONITOR > Log
19
Make sure the both ZyWALL/USG at the HQ and Branch sites security policies allow
IPSec VPN traffic. IKE uses UDP port 500, AH uses IP protocol 51, and ESP uses IP
protocol 50.
20
Default NAT traversal is enable on ZyWALL/USG, please make sure the remote
IPSec device must also have NAT traversal enabled.
www.zyxel.com
97/255

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents