How to configure IPv6 IPSec VPN (USG FLEX/ATP)

Zyxel_Kay
Zyxel_Kay Posts: 1,199  Zyxel Employee
Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

Scenario:

This guide explains how to set up an IPv6 IPsec VPN connection between two locations using Zyxel USG FLEX/ATP firewalls, such as a headquarters and a branch.

Before You Begin

Ensure the IPv6 setting is enabled on your firewall. Follow this guidance article for instructions.

How to Enable IPv6 Settings on Firewall (USG FLEX/ATP) — Zyxel Community

Steps

  1. Set Up IPsec Site-to-Site VPN for HQ - Phase 1Path: CONFIGURATION > VPN > IPsec VPN > VPN Gateway > Gateway Settings
  2. Set Up IPsec Site-to-Site VPN for HQ - Phase 2Path: CONFIGURATION > VPN > IPsec VPN > VPN Connection > VPN Gateway & Policy Settings
  3. Set Up IPsec Site-to-Site VPN for Branch - Phase 1Path: CONFIGURATION > VPN > IPsec VPN > VPN Gateway > Gateway Settings
  4. Set Up IPsec Site-to-Site VPN for Branch - Phase 2Path: CONFIGURATION > VPN > IPsec VPN > VPN Connection > VPN Gateway & Policy Settings
  5. Verify VPN StatusPath: MONITOR > VPN Monitor > IPsec > IPsec

Limitations

  • Only IKEv2 is supported for IPv6 IPsec VPN.
  • No NAT support (6 in 4 or 6 in 6).
  • No L2TP over IPv6 IPsec.

Kay

See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community