[ATP/FLEX]When using Nebula VPN, the site-to-site VPN fail

Zyxel_Kevin
Zyxel_Kevin Posts: 885  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments

Symptom:

You have two firewalls in the same Org different Sites, The Site-to-Site VPN cannot build successfully.

You will see many Fragmented packets within IKE negotiation

Workaround:

Due to Nebula VPN using certificates for establishment, negotiation packets include certificates. This may result in issues with ISPs having smaller MTUs.

Please consider using a non-Nebula VPN Pre-shared key