USG1100, don't work Connectivity check on VTI
We have VTI between USG1100 & USG20W-VPN.
Net 172.24.0.0/30.
172.24.0.1 - USG1100 (v4.62)
172.24.0.2 - USG20W-VPN (v.4.63)
I configurated Connectivity check on both side, with ping other device.
Than VPN is don't connect, USG20W-VPN show that VTI & IpsecVPN is disconnected.
On USG1100 VTI & IpsecVPN in connected state, but in trunk VTI in dead state.
Why does USG1100 don't disconnect connection?
Net 172.24.0.0/30.
172.24.0.1 - USG1100 (v4.62)
172.24.0.2 - USG20W-VPN (v.4.63)
I configurated Connectivity check on both side, with ping other device.
Than VPN is don't connect, USG20W-VPN show that VTI & IpsecVPN is disconnected.
On USG1100 VTI & IpsecVPN in connected state, but in trunk VTI in dead state.
Why does USG1100 don't disconnect connection?
0
All Replies
-
Hi@alexey,By default, ESP is allowed in the security policy rule "From WAN to ZyWALL".You can check if ESP is dropped by any manually added/edited security policy rule.Go to CONFIGURATION > Security Policy > Policy Control and filter rules by:From: anyTo: ZyWALLCheck if the service ESP is allowed in the rule "From WAN To ZyWALL, source: the wan IP of the remote site".For example, on USG1100, check if ESP is allowed in the rule "From WAN To ZyWALL, source: the wan IP of USG20W-VPN".0
Categories
- All Categories
- 347 Beta Program
- 2.1K Nebula
- 115 Nebula Ideas
- 77 Nebula Status and Incidents
- 5K Security
- 44 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 64 Switch Ideas
- 900 WirelessLAN
- 33 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 326 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 832 Nebula FAQ
- 402 Security FAQ
- 219 Switch FAQ
- 190 WirelessLAN FAQ
- 45 Consumer Product FAQ
- 136 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 61 Security Highlight