-
What proposal should be configured on ATP/USG FLEX for IKEv2 native client on macOS 14 Sonoma?
Question: What proposal should be configured on ATP/USG FLEX for IKEv2 native client on macOS 14 Sonoma? Answer: Phase 1: AES256, SHA256, Key Group=DH19 Phase 2: AES256, SHA256, PFS=none
-
Why is L2TP VPN client on macOS not able to ping LAN gateway?
Question: L2TP VPN clients on macOS are connected successfully. However, they are not able to ping LAN gateway. Answer: On MacBook, you need to turn on the option “Send all traffic over VPN connection”.
-
How to collect the console log on SecuExtender IPSec VPN client?
Question: How to collect the console log on SecuExtender IPSec VPN client? Answer: The console log on SecuExtender helps us to troubleshoot the issue including connection issue, software issue, or configuration issue.
-
Is there any way to remove saved IP from Secure Extender History?
Question: Every time when we connect to a new device via SecuExtender, the IP is automatically saved to server list. The list of server IP grows gradually. Is there any way to remove saved IP from Secure Extender History? Answer: Yes, the IP information is saved to an xml file which is located at windows user's folder.…
-
Does VPN Client IPSec_SSL_VPN_7.7.40.019 work with ATP/USG FLEX?
Question: Does VPN Client IPSec_SSL_VPN_7.7.40.019 work with ATP/USG FLEX? Answer: You can use IPSec_SSL_VPN_7.7.40.019 to establish IKEv2 with ATP/USG FLEX. USG FLEX H ATP/USG FLEX IKEv2 SSL VPN IKEv2 SSL VPN IPSec_SSL_VPN_7.7.40.019 (Windows) o o o x IPSec_6.6.87.108 (Windows) o x o x
-
Android 13 strongswan IKEv2 VPN
Operation StepsTo connect to IKEv2 VPN with Android 13, please follow the steps below. 1. enable IPSec VPN server (IKEv2) at Firewall > Configure > Remote access VPN 2. Click Send Email to receive the SecuExtender IKEv2 VPN script and it's a TGB file. 3. Change the file from .tgb to .txt and open it with Notepad. 4. Remain…
-
Troubleshoot if you have site to site VPN issue
Scenario: Assuming the Tunnel built successfully but there are some traffic/unstable/disconnecting issues. Checking: 1)Reauth action must ahead of Rekey, Please check phase1 lifetime greater than phase2. 2)Recommend to use ikev2 beacuse it implements a more complete rekey mechanism to prevent tunnel reconect.
-
How to install IKEv2 VPN script to iPhone?
Zyxel Firewall allows users to download the VPN script for iOS/macOS, how do we install the .mobileconfig file to iPhone? To install the mobileconfig file, you may download it on your iPhone, and then Save to Files Then go to VPN & Device Management, you will a download profile, please click on it and install it.
-
How can we check the Windows L2TP VPN connection log when troubleshooting a connection issue?
Question: How can we check the Windows L2TP VPN connection log when troubleshooting a connection issue? Answer: Press Win + X and select "Event Viewer" from the menu. In the Event Viewer window, expand "Windows Logs" in the left pane and select "Applicatoin." Filter the event log by the source "RasClient". You will be able…
-
Why Windows 11 build-in L2TP/IPSec VPN is slow in both download and upload activity?
Question Some users have encountered Windows build-in L2TP/IPSec VPN slow performance issues recently. Why would this happen? Answer It could be affected by the Patch updates of Windows update KB5025305 which is acknowledged by the company that cause problems with L2TP/IPsec VPN connections on Windows 11 PCs. It’s…
-
Why am I receiving an incorrect username/password error when connecting to SSL VPN?
Question Sometimes, I can confirm the username/password is correct, but when I try to connect to SSL VPN, I still get an error showing "incorrect username/password", and the logs also show this kind of information. why would this happen? Answer: There are two scenarios you would get rejected by incorrect username/password…
-
How to allow SSL VPN clients to access some internal servers only but not all local networks?
Question: How to allow SSL VPN clients to access some internal servers only but not all local networks? Answer: Disable “Force all client traffic to enter SSL VPN tunnel”. If “Force all client traffic to enter SSL VPN tunnel” is enabled, the setting of Network List will be ignored. It means SSL VPN clients are allowed to…
-
How to allow L2TP VPN when WAN interface doesn't exist in default WAN trunk?
QUESTION In this scenario, the WAN interface for L2TP connection does not exist in the default WAN trunk, how to allow L2TP VPN such a WAN interface that is not in the default WAN trunk? ANSWER You can add policy routes to resolve this situation because policy route priority is higher than the default WAN trunk. Policy…
-
Why no traffic pass through the tunnel as it's established?
Question: Why no traffic pass through the tunnel as it's established? Answer: 1.Make sure to allow ESP from WAN to Device. Without allowing ESP, the firewall cannot unencrypt encapsulated packets. Check Policy Route/Static Route. Check if any policy routes or static routes that could interfere with routing traffic into the…
-
What's the purpose of Auto disable VPN service?
Question: What's the purpose of Auto disable VPN service? Answer: This option means disabling UDP ports 500 and 4500 from WAN to ZyWall when no IPSec VPN rules are configured on your device. This option helps to prevent hackers from attacking your device through UDP 500 and 4500 when you're not using IPsec VPN.
-
How to build dual WAN site to site VPN tunnel
Branch office won’t lost access if headquarter primary WAN is dead Setting In Headquarter: Phase1: My Address: 0.0.0.0 Peer Address: Dynamic Address Phase2: Application Scenario: Remote Access (Server Role) Select server role will force Headquarter respond negotiation only. It is helpful to decrease headquarter loading.…
-
How to use L2TP VPN client to connect to an intranet PC using VNC software?
Background and Scenario: Sometimes, we might need to use the L2TP VPN client to connect to an intranet PC via VNC for handling some office tasks. Answer: Please refer to the below lab: Topology: (WAN:10.214.48.135) PC : L2TP client (192.168.50.1) => (WAN:10.214.48.25)USG Flex200 => LAN1=>PC :Ultra VNC server(192.168.1.121)…
-
How to use CLI to check the current VPN connection status?
Background and Scenario: After establishing the site-to-site VPN and L2TP VPN connections, how can you use CLIs to check the current VPN connection status? Answer: You can use the commands "show sa monitor" and "show sa counter" to display the current VPN tunnel connection status and the number of VPN tunnels.
-
What does "Network Extension Local IP" mean?
Question: In CONFIGURATION > VPN > SSL VPN > Global Setting, Network Extension Local IP is 192.168.200.1. Can I assign IP pool for SSL VPN as 192.168.200.0/24? Answer: This IP address is SSL VPN interface. After the SSL VPN is established in the client successfully, it will create a routing for SSL VPN pool IP address. To…
-
How do I enable trace mode in Zyxel IP sec VPN client?
Question Assume we encounter some issues on Zyxel IP sec VPN client How do I enable trace mode to gather more log on IP sec VPN client? Answer Please send shortcuts key Ctrl+Alt+T to enable trace mode on Zyxel IP sec VPN client, The log will store at C:\ProgramData\Zyxel\ZyWALL IPSec VPN Client\LogFiles").