Cannot connect VPN IKEv2 to usg 100

Franz94370
Franz94370 Posts: 8  Freshman Member
First Comment First Anniversary

I have configurate a IKEv2 VPN connection but each time i cannot connect and i saw this error message in the log

1

2024-10-17 07:55:12

warn

ADP

Rule_id:1 from WAN to Any, [type:UDP-Decoder(74)] oversize-len Action:Drop Packet [count=3]

V5.39(ABUH.0) / 2024-08-22 06:21:11

Can you help me ?

Best regards

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,595  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Franz94370,

    This is more likely due to the other side of the IKEv2 VPN sending over-size-length packets. What is the device that connects to USG FLEX 100? If it is site-to-site VPN, are the VPN configurations on both the routers/firewalls the same? (MSS)

    In addition, if this device is trusted, you can set the ADP allow list to bypass the traffic. The rules below screenshot an example, you might need to adjust to fit your network.

    Hope it helps.

    Zyxel Melen


  • Franz94370
    Franz94370 Posts: 8  Freshman Member
    First Comment First Anniversary

    Thank you for your answer.

    I tried to create the rules but cannot connect.

    Configuration is VPN Client to site.

    I try tout connect on a Win10 Pc using the built in Windows client

    The USG is connected upstream on a Dray Tech router and a DMZ has been configurate on 192.168.8.2 and my computer IP is 90.0.142.50

    I am sending you log of the screen

    shot

    I have tried to modify the parameter UDP LEN ATTACK in ADP but it is the same.

    What can you suggest

  • PeterUK
    PeterUK Posts: 3,461  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited October 18

    Disable ADP and see if it connects 

    is the connecting device set with Jumbo packet disabled or set to 1514