Zyxel Nebula SD VPN connection fails

IctPk
IctPk Posts: 10 image  Freshman Member
First Comment Fourth Anniversary
edited October 22 in Nebula

Hello all,

any ideas on what is going wrong?

I have 3 Sites.

Two Sites have a Flex200 router, 1 Site still has a NSG100 router (soon to be replaced).

I have Hub/Spoke Nebula SD VPN connection.

Flex 200 to Flex 200 is going well.

Flex 200 to NSG 100 is not going well (Anymore, it used to work in the passed).

The NSG 100 Event log gives me:

IPsec SA negotiation failed

No proposal chosen

Tunnel [S22F4ED88D6_21] Phase 1 Local ID mismatch

I have tried to delete all VPN settings. Turn of VPN. etc.

On all 3 devices only WAN1 is enabled. WAN2 is set to None.

I hope someone has the solution?

Thanks Very Much.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,990 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @IctPk

    May you enable Zyxel support access and share the organization's name with me so I can help to check?

    Zyxel Melen


  • IctPk
    IctPk Posts: 10 image  Freshman Member
    First Comment Fourth Anniversary

    Dear Zyxel Melen. Thanks for your answer. The Org name is: Stichting PK

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,990 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited 2:59AM

    Hi @IctPk

    Thanks for the privilege. This is because the device's VPN configuration error that cause Nebula can't push the new VPN configuration. Please find an available time to remove the NSG from this site and add it back. This will erase the device's old configuration and push the new configuration.

    image.png
    Zyxel Melen


  • IctPk
    IctPk Posts: 10 image  Freshman Member
    First Comment Fourth Anniversary

    Thanks again for your suggestions. Do I need to be on site to do this? Or is it possible to do from remote?

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,990 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @IctPk

    It is possible to do from remote. The steps keep NSG's WAN interface setting; therefore, the device will still connect with Nebula.

    Zyxel Melen


Nebula Tips & Tricks