Troubleshooting; Chapter 52 Troubleshooting - ZyXEL Communications ZyWALL USG 300 User Manual

Unified security gateway
Hide thumbs Also See for ZyWALL USG 300:
Table of Contents

Advertisement

C
H A P T E R
This chapter offers some suggestions to solve problems you might encounter.
• You can also refer to the logs (see
• For individual log descriptions,
For the order in which the ZyWALL applies its features and checks, see
page
37.
I cannot set up an IPSec VPN tunnel to another device.
If the IPSec tunnel does not build properly, the problem is likely a configuration
error at one of the IPSec routers. Log into both ZyXEL IPSec routers and check the
settings in each field methodically and slowly. Make sure both the ZyWALL and
remote IPSec router have the same security settings for the VPN tunnel. It may
help to display the settings for both routers side-by-side.
Here are some general suggestions. See also
• The system log can often help to identify a configuration problem.
• If the sites are/were previously connected using a leased line or ISDN router,
physically disconnect these devices from the network before testing your new
VPN connection. The old route may have been learnt by RIP and would take
priority over the new VPN connection.
• To test whether or not a tunnel is working, ping from a computer at one site to
a computer at the other.
Before doing so, ensure that both computers have Internet access (via the
IPSec routers).
• It is also helpful to have a way to look at the packets that are being sent and
received by the ZyWALL and remote IPSec router (for example, by using a
packet sniffer).
Check the configuration for the following ZyWALL features.
• The ZyWALL does not put IPSec SAs in the routing table. You must create a
policy route for each VPN tunnel. See
• Make sure the To-ZyWALL firewall rules allow IPSec VPN traffic to the ZyWALL.
IKE uses UDP port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
ZyWALL USG 300 User's Guide

Troubleshooting

Chapter 52 on page
Appendix A on page
835.
Chapter 21 on page
Chapter 12 on page
52
823).
Section 2.2 on
353.
259.
823

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents