IPSecVPN - Cannot ping remote IP range

CRP0499
CRP0499 Posts: 16  Freshman Member
First Comment Fourth Anniversary

I have a Zyxel 1100 at SiteA and a USG 220 at SiteB.

I used the wizards to congifure my site to site IPSecVPN and it's working in that it came up immediately on both sides.

My problem is I cannot ping any IP addresses on either side. I can't even ping the Zyxels on each side.

Both devices are new and I have not cluttered the things with guesses at fixes, but I feel like I'm missing something simple like a policy or a check mark somewhere.

I did not add any additional security policies. I just let the wizards do everything, and that's where I am now. I am unable to ping IP addresses behind each firewall.

Can someone tell me please what I missed?

Thank you

Accepted Solution

  • CRP0499
    CRP0499 Posts: 16  Freshman Member
    First Comment Fourth Anniversary
    Answer ✓

    So, this is working now. What did I do you may ask? Nothing!

    I built out the IPSec VPN connections in each firewall and it did not work.

    I posted here.

    I went in this AM, deleted my two IPSec VPN connections (one out of each firewall) and then added them back.

    It's working as expected now.

All Replies

  • CRP0499
    CRP0499 Posts: 16  Freshman Member
    First Comment Fourth Anniversary
    edited March 24

    Posted reply in error

  • PeterUK
    PeterUK Posts: 3,326  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Devices need to allow ICMP inbound on there firewall for one.

    you maybe need a routing rule above any other rules like LAN1 next hop WAN with a rule above LAN1 destination subnet of IPs over the tunnel and next hop VPN tunnel

    security policies like LAN1 to VPN zine and VPN zone to LAN1

  • Zyxel_James
    Zyxel_James Posts: 663  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    @CRP0499 three major mistakes may cause the traffic not to go through the tunnel.

    Please refer to this article for further troubleshooting first, thanks.

  • CRP0499
    CRP0499 Posts: 16  Freshman Member
    First Comment Fourth Anniversary

    Thank you James. I do believe I understand the article. What I would like clarity on is I have TWO IPSec VPN tunnels in the 1100. The first tunnel I set up is working as expected. Traffic is flowing and pings are passing.

    When I set up the second tunnel, I cannot ping across it.

    My trace route shows my pings first hop as the first vpn tunnel, so, I'm thinking I need routes to tell traffic where to go.

    With just one VPN tunnel, things work great. When I add the second vpn tunnel, that's where things begin to break down.

  • CRP0499
    CRP0499 Posts: 16  Freshman Member
    First Comment Fourth Anniversary
    Answer ✓

    So, this is working now. What did I do you may ask? Nothing!

    I built out the IPSec VPN connections in each firewall and it did not work.

    I posted here.

    I went in this AM, deleted my two IPSec VPN connections (one out of each firewall) and then added them back.

    It's working as expected now.

  • PeterUK
    PeterUK Posts: 3,326  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Do you have different IP subnet on different sites such that you don't have 192.168.1.0/24 on on another site or enabled interface which such a subnet?

Security Highlight