[ATP/FLEX]When using Nebula VPN, the site-to-site VPN fail

Options
Zyxel_Kevin
Zyxel_Kevin Posts: 754  Zyxel Employee
First Anniversary 10 Comments Friend Collector First Answer

Symptom:

You have two firewalls in the same Org different Sites, The Site-to-Site VPN cannot build successfully.

You will see many Fragmented packets within IKE negotiation

Workaround:

Due to Nebula VPN using certificates for establishment, negotiation packets include certificates. This may result in issues with ISPs having smaller MTUs.

Please consider using a non-Nebula VPN Pre-shared key