SecuExtender IPSec Windows VPN client suddently will not connect
Hi,
For remote access, we use the SecuExtender IPSec client, running on a Win11 PC. It's connecting to a VPN100 at the main office, and it has been running without troubles for a long time, but suddently after at Windows restart, propbably in connection with Windows Updates, the client is not able to connect anymore.
I have tried to do a reprovisioning, and aquring the configuration from the VPN100 still possible.
When hitting [Open tunnel], it seems from the log, that it retry something 3 times before connection is aborted (logfile attached)
Any idea what could be wrong?
Best regards Ole.
All Replies
-
Well, I am not an expert when it comes to VPN and IKE, but I can suggest what would be the 3 things repeated before connection is aborted:
SEND IKE_SA_INIT request MID=0000 (rest of line intentionally omitted)
SEND IKE_SA_INIT repeat MID=0000 (rest of line intentionally omitted)
SEND IKE_SA_INIT repeat MID=0000 (rest of line intentionally omitted)
3 attempts with no response. Aborting connection.
By the way: those lines saying "No SSL configuration", do you know if they were present before, when it worked? Or for that matter, do you have any logs saved from before when it worked?
Best regards,
Trond0 -
The way I read it is your not using SSL by IKEv2 and from the looks of it the client can't get to the VPN100?
Has the IP changed? is the self signed cert in date if using?
0 -
Hi,
Thank you for the replies.
@smb_corp_user unfortunately I do not have a log from when it worked. The PC is doing an auto reboot every morning 6:00, and from what I can find out, the log is cleared when the IPSec client is restarted. I noticed the mention of "No SSL configuration" and wondered what that means, since it's an IPSec connection.
@PeterUK The static WAN IP of the VPN100 have not changed, configuration provisioning is still possible, and you are acquiring the configuration from the VPN100 by WAN IP and SSL. Certificate is self-signed and renewed back in august and last for 2 years.
BR O
0 -
Hi @OWB,
To narrow down the cause, please check the following:
- Verify connectivity to the VPN gateway
- Ensure the client can reach the VPN100's IP address (perform a ping test to confirm the target IP is valid).
- Confirm UDP ports 500 and 4500 are not blocked
- These ports must be reachable end-to-end for IKEv2/IPSec. Please ensure UDP ports 500 and 4500 are open.
- Additionally, please check the Event Log to identify which segment of the connection is experiencing the issue.
- Check Windows Firewall or security software
- Windows updates can sometimes modify local firewall rules. Temporarily disable it to test if it's affecting the VPN connection.
- Validate certificate settings
- Ensure the client is using the correct and valid certificate after the update.
In addition, please provide the Windows 11 build number and details of recent Windows Updates (KBs) installed, as certain updates may affect VPN components.
Zyxel Tina
0 - Verify connectivity to the VPN gateway
Categories
- All Categories
- 440 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 528 USG FLEX H Series
- 331 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 50 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.6K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member
Master Member
Guru Member
Zyxel Employee