USG60 <> USG200 Site2Site VPN stopped working after WAN IP change
We changed the WAN IP on our USG200 site today.
I thought I just needed to change the IP in the VPN configuration on both ends and it would work. For our other Site2Site VPN between two USG200s, this has worked. But the connection between the USG60 (site handle "LHS") and USG200 (site handle "MOL") do seem to connect as the icons show a "connected" status, but the USG200 is not receiving any packages from the USG60 (other direction lists traffic … see screenshot below). Regardless, the USG60 can not ping servers in the USG200 network anymore since the change.
I'll drop a couple of details following.
Here are the USG60 "LHS" gateway settings:
Here are the USG60 "LHS" connection settings:
Here are the USG200 "MOL" gateway settings
Here are the USG200 "MOL" connection settings
In the VPN monitor, the USG60 lists sent and received packages. Additionally, this connection has a greyed out "Connection Check" button.
In the VPN monitor of the USG200, it only lists sent packages but no received packages. The "Connection Check" button is working here, but I am getting a timeout.
Both show uptimes that are basically identical, making me think that the connection itself works.
I checked the PSKs and the respective WAN IPs, of course, and they seem to match. Curiously, the USG60 has a working VPN connection to our other office, which is also a USG200 (but the IP didn't change there). The settings for both connections are identical, aside from the different WAN targets and subnets at the target site.
The IKE logs show correct key handshakes. No errors in the IPsec logs, which I really do not understand. I must be missing something, but I can't figure out what. Anyone have any pointers?
- All Categories
- 199 Beta Program
- 1.8K Nebula
- 94 Nebula Ideas
- 63 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 52 Switch Ideas
- 919 WirelessLAN
- 28 WLAN Ideas
- 5.4K Consumer Product
- 173 Service & License
- 296 News and Release
- 114 Success Stories
- 65 Security Advisories
- 14 Education Center
- 1K FAQ
- 454 Nebula FAQ
- 258 Security FAQ
- 100 Switch FAQ
- 115 WirelessLAN FAQ
- 22 Consumer Product FAQ
- 70 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 69 About Community
- 52 Security Highlight