site-to-site vpn, no communication

blubber007
blubber007 Posts: 3  Freshman Member
First Comment

Having two USG Flex 100 and an VPN connection using IPSec with a pre-shared password. Latest firmware installed.
We need 5 VLAN connected to both sides (branch and central).
Subnet1 central: 10.7.1.0/24
Subnet1 branch: 10.8.1.0/24
Subnet2 central: 10.7.2.0/24
Subnet2 branch: 10.8.2.0/24
etc.
VPN tell me, it's connected, but I don't have traffic or ping.

What am I doing wrong?

What is the viable way to connect multiple VLANs? Multiple VPNs?

Thanks!

Accepted Solution

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,199  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @blubber007

    Based on the information we have so far, it's difficult to determine whether the issue is related to routing or the current security policy configuration. For further troubleshooting, you could try temporarily disabling the policy control and checking if the VPN traffic forwards normally.

    If disabling the policy control resolves the issue, we can narrow down the problem to the security policy settings. However, if the VPN traffic still doesn't work after disabling it, we may need to investigate further, focusing on your policy route or static route configuration.

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,199  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @blubber007

    To better assist you with troubleshooting the VPN issue, could you kindly provide the following information:

    1. A more detailed screenshot of your security policy configuration. The initial one you provided seems to cover only a small part of the setup.
    2. Additionally, please share a screenshot of the relevant event logs when one of the site-to-site VPN connections is established.

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • blubber007
    blubber007 Posts: 3  Freshman Member
    First Comment

    Thanks for very fast answer. I copy all information to document and would be happy, if you have the rigth idea for me. The data of document collected by branch FW. If you like, I can give you remote access.

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,199  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @blubber007

    Based on the information we have so far, it's difficult to determine whether the issue is related to routing or the current security policy configuration. For further troubleshooting, you could try temporarily disabling the policy control and checking if the VPN traffic forwards normally.

    If disabling the policy control resolves the issue, we can narrow down the problem to the security policy settings. However, if the VPN traffic still doesn't work after disabling it, we may need to investigate further, focusing on your policy route or static route configuration.

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

Security Highlight