Remote Access IPSEC VPN doesn't work

Jerome89
Jerome89 Posts: 3 image  Freshman Member
First Comment

Hello,

I did setup Remote Access IPSec VPN using SecuExtender. I can't make it work. To troubleshoot I connected the client directly to the wan network of the USGFlex200 (192.168.250.50/24) . Here is attached the SecuExtender console output. I'm a new Zyxel user, so I probably have missed something obvious in the configuration (even if I used the wizard) ?

Thanks in advance,

Best regards,

Jerome

All Replies

  • PeterUK
    PeterUK Posts: 4,132 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    With the wizard did you select IKEv2?

  • Jerome89
    Jerome89 Posts: 3 image  Freshman Member
    First Comment

    Yes IKEv2. Wizard screenshots attached.

  • PeterUK
    PeterUK Posts: 4,132 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Log are saying Self-signed certificate not accepted, on SecuExtender are you using the "get from server" under configuration?

  • Zyxel_Tina
    Zyxel_Tina Posts: 286 image  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Jerome89,

    Welcome to Zyxel Community!

    After analyzing, your USG FLEX is using a self-signed certificate with a private WAN IP.

    Since this is not a public IP, the VPN gateway is likely behind another router, causing the certificate validation and IKEv2 negotiation to fail.

    Please check the following:

    • Make sure the USG FLEX has a public IP or that UDP ports 500 and 4500 are forwarded from the upstream router.
    • Use a certificate whose CN matches the public IP used by the client.

    The VPN should connect if the gateway is reachable on a valid public address.

    Zyxel Tina