USG1100, don't work Connectivity check on VTI

alexey
alexey Posts: 188  Master Member
First Anniversary 10 Comments Friend Collector
edited July 2021 in Security
We have VTI between USG1100 & USG20W-VPN.
Net 172.24.0.0/30.
172.24.0.1 - USG1100 (v4.62)
172.24.0.2 - USG20W-VPN (v.4.63)
I configurated Connectivity check on both side, with ping other device.
Than VPN is don't connect, USG20W-VPN show that VTI & IpsecVPN is disconnected.
On USG1100 VTI & IpsecVPN in connected state, but in trunk VTI in dead state.
Why does USG1100 don't disconnect connection?

All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Hi@alexey,

    By default, ESP is allowed in the security policy rule "From WAN to ZyWALL".
    You can check if ESP is dropped by any manually added/edited security policy rule.
    Go to CONFIGURATION > Security Policy > Policy Control and filter rules by:
    From: any
    To: ZyWALL

    Check if the service ESP is allowed in the rule "From WAN To ZyWALL, source: the wan IP of the remote site".
    For example, on USG1100, check if ESP is allowed in the rule "From WAN To ZyWALL, source: the wan IP of USG20W-VPN".




Security Highlight