Site to site Route-based and Policy-based to same IP link issue
USG FLEX200HV1.21(ABWV.0)
setup is USG60W
LAN2 192.168.254.9 255.255.255.248
Gwtoflex200H_local2 Site-to-site with Dynamic Peer
Pre-Shared Key 123456789
Phase 1 AES128 SH1 DH2
local policy192.168.252.0/23
remote policy192.168.255.64/28
Phase 2 AES128 SH1 DH2
VTI_test
IP 192.168.254.10
Pre-Shared Key 12345678
Phase 1 AES128 SH256 DH2
Phase 2 AES128 SH1 DH2
VTI IP 192.168.255.43 255.255.255.240
FLEX200H
Ge3 WAN3 192.168.254.10 255.255.255.248 gateway 192.168.254.9
P4 VLAN47 192.168.255.39 255.255.255.240
P4 VLAN48 192.168.255.65 255.255.255.240
TuneltoUSG60W_local3 Site-to-site Policy-based
Pre-Shared Key123456789
Phase 1 AES128 SH1 DH2
local policy192.168.255.64/28
remote policy192.168.252.0/23
Phase 2 AES128 SH1 DH2
Nailed-up
VTI Route-based
IP 192.168.254.9
Pre-Shared Key 12345678
Phase 1 AES128 SH256 DH2
Phase 2 AES128 SH1 DH2
VTI IP 192.168.255.42 255.255.255.240
Nailed-up
So here is what happens disable Gwtoflex200H_local2 on USG60W and connect the VTI Route-based on FLEX200H connects fine then enable Gwtoflex200H_local2 and connect TuneltoUSG60W_local3 Site-to-site Policy-based it connects fine but if I disable VTI on Flex200H then enable it the VTI does not connect until you disable Gwtoflex200H_local2 and start over.
Accepted Solution
-
Ok solved it on how you can do this after testing with USG60W to FLEX200 the above don't work so there are two ways One is to have one IKEv1 and the other IKEv2 or if you want both IKEv2 you have the mismatch both Phase 1 and Phase 2 like I only did Phase 1 at the start.
VTI Route-based
Phase 1 AES128 SH256 DH2
Phase 2 AES128 SH256 DH2
Site-to-site Policy-based
Phase 1 AES128 SH1 DH2
Phase 2 AES128 SH1 DH2
Tested between USG60W and FLEX200H with ping
0
All Replies
-
Ok solved it on how you can do this after testing with USG60W to FLEX200 the above don't work so there are two ways One is to have one IKEv1 and the other IKEv2 or if you want both IKEv2 you have the mismatch both Phase 1 and Phase 2 like I only did Phase 1 at the start.
VTI Route-based
Phase 1 AES128 SH256 DH2
Phase 2 AES128 SH256 DH2
Site-to-site Policy-based
Phase 1 AES128 SH1 DH2
Phase 2 AES128 SH1 DH2
Tested between USG60W and FLEX200H with ping
0 -
Hi @PeterUK
but if I disable VTI on Flex200H then enable it the VTI does not connect until you disable Gwtoflex200H_local2 and start over.
Could you please share the IKE logs from both devices so we can investigate further?
Kay
Engage in the Community, become an MVP, and win exclusive prizes! https://bit.ly/Community_MVP
0 -
Hi Kay
I solved it as said above
0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight