How to Resolve RADIUS Authentication Issues over route based VPN on FLEX H Series

Zyxel_Kevin
Zyxel_Kevin Posts: 903  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments
edited February 4 in VPN

Question: Why is my FLEX H series device unable to reach the RADIUS server over route based VPN

Topology:

FLEX H series <Site to Site VPN> Peer Gateway - Radius server

Answer: 

For local out traffic, FLEX H used the VTI address as inquiry source address

Below are steps to troubleshoot and resolve the issue:

  1. Ensure the Radius server can route and trusts the VTI interface address used by the FLEX H device. 
  2. Ensure VTI address settings are within the subnet and do not use link-local addresses:
  • Use a valid subnet for the VTI interface (e.g., 192.168.254.x) instead of link-local addresses such as 169.254.0.0/16.

      (Some Operate System cannot route link-local address)

If additional assistance is required, or if you need to share logs and packet captures, please provide information such as packet captures on the VTI interface when authentication is attempted. This will help diagnose any further issues more effectively.