USG FLEX 200H – IKEv2 Remote Access VPN client shows Connected but FLEX does not establish any IKE/I
Freshman Member
We are experiencing an issue with IKEv2 Remote Access VPN on a Zyxel USG FLEX 200H.
The VPN client may show "Connected", but the USG FLEX does not establish or maintain any IKE/IPsec Security Association, and the client cannot access the configured internal network.
Device information
Model: Zyxel USG FLEX 200H
Firmware: V1.39(ABWV.0)
Running partition: 2
WAN interface: FPT_PPP
WAN public IP: 183.80.161.10
VPN configuration
VPN type: IKEv2 Remote Access VPN
Interface: FPT_PPP (WAN)
NAT Traversal: Disabled
Zone: IPSec_VPN
Server certificate: RemoteAccess_VPN_RSA
Authentication: Local user authentication
VPN user: sonc
Client network:
10.10.1.0/24
Local network accessible through VPN:
10.8.1.0/24
IKE Phase 1:
AES256-CBC
SHA256
DH Group 14
Lifetime: 86400 seconds
IPsec Phase 2:
AES256-CBC
SHA256
PFS: None
Lifetime: 28800 seconds
Split tunnel: Enabled
Problem description
The Windows/iPhone VPN client attempts to establish an IKEv2 connection.
In packet capture, we can see the client sending IKE_SA_INIT packets to:
103.x.x.x -> 183.80.161.10:500/UDP
However, the USG FLEX does not appear to respond to the IKE_SA_INIT request.
We also tested from different Internet connections, with the same result.
At one point the client UI reported "Connected", but immediately checking the USG FLEX showed:
show ike ike-sa
No IKE SA.
show ike ipsec-sa-count
0
show state vrf main ike
ike-sa
total 0
half-open 0
counters
ike-init-in-req 0
ike-init-in-resp 0
ike-init-out-req 0
ike-init-out-resp 0
ike-auth-in-req 0
ike-auth-in-resp 0
ike-auth-out-req 0
ike-auth-out-resp 0
create-child-in-req 0
create-child-in-resp 0
create-child-out-req 0
create-child-out-resp 0
So the USG FLEX appears not to register the IKE negotiation at all.
Troubleshooting already performed
- WAN connectivity
The FPT_PPP interface is UP and has the public IP:
183.80.161.10
The VPN interface is explicitly bound to FPT_PPP.
- WAN security policy
The existing system WAN-to-ZyWALL policy already allows:
- IKE / UDP 500
- NAT-T / UDP 4500
- ESP
- AH
We verified that the VPN connection attempts do not increase the security-policy drop counter.
- IKE/IPsec counters
IKE counters remain at zero during/after the connection attempt.
There is no IKE SA, half-open SA, or IPsec SA.
- DoS protection
IKE DoS protection is enabled, but:
- half-open SA count = 0
- init-limit-half-open = 0
- no evidence that the client IP is blocked
- IP Reputation
IP Reputation is enabled, but the block list does not contain the client IP.
- Certificate
We initially used an older certificate.
We generated and tested a new RSA certificate:
RemoteAccess_VPN_RSA
The certificate is:
- RSA 2048
- SHA256
- Server Authentication
- Client Authentication
- IKE Intermediate
- SAN contains the public IP 183.80.161.10
After changing to this certificate, the USG FLEX was able to successfully generate/export the native Windows IKEv2 configuration ZIP.
However, the VPN connection problem remains.
- Authentication
We removed AD/Samba authentication from the troubleshooting path and changed the VPN authentication backend to a local USG FLEX user.
Current VPN user:
sonc
Therefore the current test does not depend on our Samba AD/LDAP configuration.
- VPN profile
The native Windows VPN profile generated by the USG FLEX was installed and tested.
The profile is configured as:
- IKEv2
- EAP
- Split tunneling
- Route: 10.8.1.0/24
- AES256/SHA256
- DH Group 14
Windows reports the VPN connection as terminated by the remote computer during the failed attempts.
- Packet capture
Packet captures show the client sending IKE_SA_INIT packets toward:
183.80.161.10 UDP/500
but no corresponding response from the USG FLEX was observed.
- Zyxel IPsec debug
We also used the official IPsec debug/trace mechanism:
cmd debug ipsec trace log
During the problematic attempts, there were no normal IKE negotiation events such as NET/IKE processing of the incoming IKE_SA_INIT request. Only periodic housekeeping messages such as:
[IKE] rechecking in 10s
were observed.
- System services
The IPsec/IKE related processes are running, including:
- charon-systemd
- radiusd
- fptun-nfqd
- Fast-path resources
We checked fast-path CPU, memory and table utilization.
There is no indication of resource exhaustion.
The IPsec SA table is not exhausted.
Additional observation
The system log contains some fast-path messages such as:
[NFTABLE] Failed to get in_if_property for lo
and one:
[CONNTRACK] Failed to process packet for connection tracking for proto 6
However, we have not established a direct relationship between these messages and the IKEv2 problem.
Firmware
The device is currently running:
V1.39(ABWV.0)
We understand that V1.39 contains several VPN-related fixes, but we do not want to assume that the firmware is the cause without further evidence.
We would appreciate Zyxel engineering/support assistance in determining why the FLEX 200H is not processing the incoming IKE_SA_INIT packets.
Questions for Zyxel Support
- Why would the FLEX 200H receive/see IKEv2 traffic at the WAN interface but show:ike-init-in-req = 0and no IKE SA / half-open SA?
- Is there any internal service, process, fast-path component, IPsec subsystem, or configuration state that could prevent charon/strongSwan from receiving or processing UDP/500 traffic?
- Are there any known issues with IKEv2 Remote Access VPN on USG FLEX 200H running V1.39(ABWV.0)?
- Could the current V1.39 firmware or IPsec/IKE subsystem require a service restart or have a known state/configuration issue?
- Is there a recommended diagnostic command or procedure that can capture the IKE packet processing path from WAN interface -> fast-path -> IKE/charon?
- If necessary, can you review our configuration/system logs and determine whether the issue is related to the firmware or IPsec subsystem?
We can provide the following if required:
- Configuration backup
- Packet capture
- IPsec debug output
- System log
- Screenshots of the VPN configuration
- Firmware/version information
Please advise what additional diagnostic information you need from the device.
Thank you.
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 241 Nebula Ideas
- 6.8K Security
- 755 USG FLEX H Series
- 380 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 321 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 90 About Community
- 119 Security Highlight