IPsec VPN problem

IT_Field_Support
IT_Field_Support Posts: 97  Ally Member
Fourth Anniversary Friend Collector First Comment
edited April 2021 in Security

Hi guys,


Just a quick question. We have one VPN gateway used by 2 phases 2 on a USG40W as we have on many other router without any problem.

On this one, for an unknown reason, phase 2 are never connected both at the same time, there are dropping all the time, sometime we can ping through these phase 2 but it is very unstable.

I tried with firewall off and it's still the same.

In the debbug logs, I notice some weird error regarding IPSec, why would IPSec drop packet ?


Thanks for help,


Davy

IPSec Dropping packet. ret=1, step=11    
IPSecSPI: 0x0 (0) SEQ: 0x0 (0) No rule found, Dropping TCP packet. ret=1, step=11
IPSec Dropping packet. ret=1, step=11
IPSec SPI: 0x0 (0) SEQ: 0x0 (0) No rule found, Dropping UDP packet. ret=1, step=11


All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,370  Zyxel Employee
    Sixth Anniversary 1000 Comments 100 Answers Zyxel Certified Sales Associate
    @IT_Field_Support,

    I've applied your configuration file to USG40W to run the test.

    The test result is sent to you in the private message.

    Best regards,
    Emily

    Don't miss this great chance to upgrade your Nebula org. For free! https://bit.ly/4g2pS9L

  • Irfan
    Irfan Posts: 3  Freshman Member
    First Anniversary First Comment
    Hello ,

    On zyxel wal usg50 getting this erro
    IPSec SPI: 0x0 (0) SEQ: 0x0 (0) No rule found, Dropping UDP packet. ret=1, step=11
    any help?
    
    Thanks
  • Zyxel_Emily
    Zyxel_Emily Posts: 1,370  Zyxel Employee
    Sixth Anniversary 1000 Comments 100 Answers Zyxel Certified Sales Associate

    Hi @Irfan,

    What is the model of the remote site of VPN tunnel?

    Could you share startup-config.conf of USG50 and topology with me in private message?

    Best regards,
    Emily

    Don't miss this great chance to upgrade your Nebula org. For free! https://bit.ly/4g2pS9L

  • Irfan
    Irfan Posts: 3  Freshman Member
    First Anniversary First Comment
    Hi,

    Ok thanks , now i upgrade USG50 with latest firmware which you sent me..
    Than let you know.
    Thanks

Security Highlight