Unable to Duplicate Working USG500H-ATP200 VPN for Add'l Site

Options
MeatPopsicle
MeatPopsicle Posts: 14 image  Freshman Member
First Comment Fourth Anniversary

Fairly new USG500H is not connecting to a remote ATP200 over site-to-site VPN. Both devices are being managed via NCC. The ATP200 is a fresh enrollee and had to be reconfigured as a result.

On the USG500H, I have duplicated a working manual-link VPN settings (using the gateway/remote address of the remote site) and it will not even allow me to save the config from NCC. I had to use the local web interface to duplicate this config.

The working VPN remote device not enrolled in NCC. I would like to have all devices enrolled in NCC.

Working USG500H Main VPN config:

IKEv2
Police-based
ge2 (WAN)
Peer address is correct
Zone = IPSec_VPN
PSK
Adv Phase 1:
86400
AES128/SHA1
DH2, DH14
Phase 2:
Local = same as primary LAN 192.168.0.0/22 (saved as a different object)
Remote = same as remote LAN1 172.19.10.1/24 (saved as an object)

Working Remote ATP200 (not enrolled in Nebula) config:

Nailed-up
NetBIOS over IPSec enabled
MSS adjustment = Auto
Narrowed
App Scenario: Site-to-Site
VPN Gateway = Main site public IP
Local policy - same as remote site primary LAN 172.20.10.0/24
Remote policy: same as main site primary LAN 192.168.0.0/22
Phase 2: ESP, Tunnel, AES128/SHA1, DH2, DH14
Zone: IPSec_VPN

Practically none of the settings on the non-NCC ATP200 are available on the NCC-enrolled ATP200.

So what's the trick here? Maybe I expected too much from NCC/cloud management altogether? Would I be better served to drive to the remote site, factory reset the ATP200, configure it from the local web interface, and be happy that it works?

PS: Sure would be nice if the config backup it created on enrollment could be applied to the device after enrolled.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @MeatPopsicle

    Do you mean these devices can connect site-to-site VPN when they did not enrollee in NCC? And have issue when both add to Nebula? If it is this case, please help to enable Zyxel support access and share the organization's name and site's name with us to check.

    Additionally, which firmware version is your ATP and USG FLEX H running?

    Zyxel Melen


  • MeatPopsicle
    MeatPopsicle Posts: 14 image  Freshman Member
    First Comment Fourth Anniversary
    Options

    Remote admin invite sent.

  • MeatPopsicle
    MeatPopsicle Posts: 14 image  Freshman Member
    First Comment Fourth Anniversary
    Options

    More info:

    Site-to-Site VPN #1: USG 500H to ATP200 (non-NCC) VPN is up and working.

    Site-to-Site VPN #2: was working on ATP200-ATP200 prior to upgrading Main site to USG500H. Decided to go the NCC route with this second site to minimize travel to that location.

    Tried to duplicate VPN #1 config for VPN #2 but the difference between local web interface settings and NCC settings is significant and seems to offer greatly diminished configuration options.

    I will send you a message with org+site details.

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited July 23
    Options

    Might be easier to firewall in to local from remote and then config it without NCC?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited July 24
    Options

    Hi @MeatPopsicle

    First, you can enable Nebula site-to-site VPN > Nebula SD-VPN. This reduces many configuration steps to create the site-to-site VPN

    Reference FAQ:

    Nebula VPN for H Series Firewalls — Zyxel Community

    Second, your VPN setting has some misconfiguration:

    1. USG FLEX H site is using different Proposal in Phase 1 & 2 with ATP site.
    2. USG FLEX H site is using incorrect local subnet object in Phase 2 setting with ATP site VPN setting. You need to correct the address object you set on USG FLEX H site VPN setting.
    3. ATP site is using different Phase 2 PFS group with USG FLEX H site.

    Please change these configurations first.

    Zyxel Melen