IPsec VPN Flip-Flopping when using secondary vpn gateway
Quality_Drive_Away
Posts: 14 Freshman Member
Models: USG210, USG20W-VPN, USG20-VPN
Firmware: v4.33
Our 17 remote ZyXEL sites flip-flop connection every 20-30 seconds when we add the secondary IP in the vpn gateway to connect to the corporate router's fail-over internet connection. I have worked with the corporate router vendor and the fail-over on the corporate side is configured correctly. Here is the details on that configuration if it helps to determine the ZyXEL's behavior.
On the ZyXEL side... nothing fancy. Mainly defaults; I just added the VPN connections and they work. Tried to add the secondary gateway IP and I get flip-flops. Back and forth between the Primary and Secondary vpn gateway IPs'. ~ weird behavior and could use some help getting this working right.
Thanks!
Firmware: v4.33
Our 17 remote ZyXEL sites flip-flop connection every 20-30 seconds when we add the secondary IP in the vpn gateway to connect to the corporate router's fail-over internet connection. I have worked with the corporate router vendor and the fail-over on the corporate side is configured correctly. Here is the details on that configuration if it helps to determine the ZyXEL's behavior.
On the ZyXEL side... nothing fancy. Mainly defaults; I just added the VPN connections and they work. Tried to add the secondary gateway IP and I get flip-flops. Back and forth between the Primary and Secondary vpn gateway IPs'. ~ weird behavior and could use some help getting this working right.
Thanks!
0
All Replies
-
0 -
@Quality_Drive_Away
We would like to clarify this case further, so can you collect the Log and diagnostic information for me.
Before collect Log message, please go to log&report>log settings>system log profile>enable IKE,IPSec and VPN Dashboard on debug level
Diagnostic information
Charlie0 -
I will have to do this after hours or on the weekend as it is very disruptive to the remote locations.
Do you want the logs from all 17 remote routers or will just 1 be good?
0 -
@Quality_Drive_Away
The collected information from local site and remote side should be enough.
Charlie0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight