The implicit Security Policy works for L2TP remote Client, but not for IPSec remote client

Soeren_Hvid_DK
Soeren_Hvid_DK Posts: 16  Freshman Member
First Comment

The implicit Security Policy / IP sec seems to not allow traffic to the lans, Only L2TP works .

Any idea why?

«1

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,229  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Soeren_Hvid_DK,

    This is more likely you didn't enable IPSec VPN to use VPN in the site-to-site VPN page. Please navigate to Menu > Site-wide > Configuration > Firewall > Site-to-site VPN to adjust your configuration.

    Hope it helps.

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


  • Soeren_Hvid_DK
    Soeren_Hvid_DK Posts: 16  Freshman Member
    First Comment

    Unfortunately it made no difference, IPSec still doesn't work

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,229  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Soeren_Hvid_DK,

    Could you enable Zyxel support access for me to check the configuration?

    https://community.zyxel.com/en/discussion/14234/nebula-how-to-turn-on-zyxel-support-access

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


  • Soeren_Hvid_DK
    Soeren_Hvid_DK Posts: 16  Freshman Member
    First Comment
    edited October 14

    Is enabled now

    #####Remove private info#####

    Do you need more infomation

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,229  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Soeren_Hvid_DK,

    I found that you have set two static route rules for IPSec VPN to VLAN 30. Could you delete these static route roles and test again?

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


  • Soeren_Hvid_DK
    Soeren_Hvid_DK Posts: 16  Freshman Member
    First Comment

    Yes, no problem, the router is in test stand

  • Soeren_Hvid_DK
    Soeren_Hvid_DK Posts: 16  Freshman Member
    First Comment

    Ok

    I removed the 2 static routes, i and i have tested again.

    I can connect and get this IP

    , but no traffic is allowed to the lans when 2FA is not enabled !

    if i enable 2FA , and connect there are no connection to the 2FA webpage https://172.16.50.1/weblogin/cgi?auth_type=vpn

    Some time i can connect, and some i can not connect and get this message from windows

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,229  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Soeren_Hvid_DK,

    Can I add a cloud authentication account to check this issue?

    And for the Windows error message, this error message you're encountering indicates that there may be a configuration issue with the network devices (such as firewalls, NAT devices, or routers) between your computer and the VPN server. To troubleshoot and resolve this error, you can follow these steps:

    1. Verify your internet connectivity.
    2. Delete the VPN profile and configure it again.
    3. Temporarily disable firewalls and security software.
    4. Check your local network configuration.
    5. Verify VPN protocol and port. UDP 500 and 4500, TCP/UDP 50 and 51.
    6. Try connecting from a different network.

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


  • Soeren_Hvid_DK
    Soeren_Hvid_DK Posts: 16  Freshman Member
    First Comment

    Yes you can add a account, no problem

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,229  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Soeren_Hvid_DK,

    After checking, I found:

    1. IPSec VPN disabled 2FA: I can access LAN 1 and LAN 2.
    2. IPSec VPN enabled 2FA: Windows won't popout the 2FA verify page, I have to open the browser and manually enter "https://192.168.100.1/weblogin.cgi?auth_type=vpn" to verify.
      P.S. The IP address can be one of the firewall interface IP addresses.

    The URL in the FAQ is wrong. I have updated it and please use the new URL to test.

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


Nebula Tips & Tricks