IPSecVPN - Cannot ping remote IP range
I have a Zyxel 1100 at SiteA and a USG 220 at SiteB.
I used the wizards to congifure my site to site IPSecVPN and it's working in that it came up immediately on both sides.
My problem is I cannot ping any IP addresses on either side. I can't even ping the Zyxels on each side.
Both devices are new and I have not cluttered the things with guesses at fixes, but I feel like I'm missing something simple like a policy or a check mark somewhere.
I did not add any additional security policies. I just let the wizards do everything, and that's where I am now. I am unable to ping IP addresses behind each firewall.
Can someone tell me please what I missed?
Thank you
Accepted Solution
-
So, this is working now. What did I do you may ask? Nothing!
I built out the IPSec VPN connections in each firewall and it did not work.
I posted here.
I went in this AM, deleted my two IPSec VPN connections (one out of each firewall) and then added them back.
It's working as expected now.
0
All Replies
-
Posted reply in error
0 -
Devices need to allow ICMP inbound on there firewall for one.
you maybe need a routing rule above any other rules like LAN1 next hop WAN with a rule above LAN1 destination subnet of IPs over the tunnel and next hop VPN tunnel
security policies like LAN1 to VPN zine and VPN zone to LAN1
1 -
@CRP0499 three major mistakes may cause the traffic not to go through the tunnel.
Please refer to this article for further troubleshooting first, thanks.
0 -
Thank you James. I do believe I understand the article. What I would like clarity on is I have TWO IPSec VPN tunnels in the 1100. The first tunnel I set up is working as expected. Traffic is flowing and pings are passing.
When I set up the second tunnel, I cannot ping across it.
My trace route shows my pings first hop as the first vpn tunnel, so, I'm thinking I need routes to tell traffic where to go.
With just one VPN tunnel, things work great. When I add the second vpn tunnel, that's where things begin to break down.
0 -
So, this is working now. What did I do you may ask? Nothing!
I built out the IPSec VPN connections in each firewall and it did not work.
I posted here.
I went in this AM, deleted my two IPSec VPN connections (one out of each firewall) and then added them back.
It's working as expected now.
0 -
Do you have different IP subnet on different sites such that you don't have 192.168.1.0/24 on on another site or enabled interface which such a subnet?
0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight