USG FLEX 200H – IKEv2 Remote Access VPN client shows Connected but FLEX does not establish any IKE/I

Options
congson1893
congson1893 Posts: 2 image  Freshman Member

We are experiencing an issue with IKEv2 Remote Access VPN on a Zyxel USG FLEX 200H.

The VPN client may show "Connected", but the USG FLEX does not establish or maintain any IKE/IPsec Security Association, and the client cannot access the configured internal network.

Device information

Model: Zyxel USG FLEX 200H
Firmware: V1.39(ABWV.0)
Running partition: 2
WAN interface: FPT_PPP
WAN public IP: 183.80.161.10

VPN configuration

VPN type: IKEv2 Remote Access VPN
Interface: FPT_PPP (WAN)
NAT Traversal: Disabled
Zone: IPSec_VPN
Server certificate: RemoteAccess_VPN_RSA
Authentication: Local user authentication
VPN user: sonc

Client network:
10.10.1.0/24

Local network accessible through VPN:
10.8.1.0/24

IKE Phase 1:
AES256-CBC
SHA256
DH Group 14
Lifetime: 86400 seconds

IPsec Phase 2:
AES256-CBC
SHA256
PFS: None
Lifetime: 28800 seconds

Split tunnel: Enabled

Problem description

The Windows/iPhone VPN client attempts to establish an IKEv2 connection.

In packet capture, we can see the client sending IKE_SA_INIT packets to:

103.x.x.x -> 183.80.161.10:500/UDP

However, the USG FLEX does not appear to respond to the IKE_SA_INIT request.

We also tested from different Internet connections, with the same result.

At one point the client UI reported "Connected", but immediately checking the USG FLEX showed:

show ike ike-sa

No IKE SA.

show ike ipsec-sa-count

0

show state vrf main ike

ike-sa
total 0
half-open 0

counters
ike-init-in-req 0
ike-init-in-resp 0
ike-init-out-req 0
ike-init-out-resp 0
ike-auth-in-req 0
ike-auth-in-resp 0
ike-auth-out-req 0
ike-auth-out-resp 0
create-child-in-req 0
create-child-in-resp 0
create-child-out-req 0
create-child-out-resp 0

So the USG FLEX appears not to register the IKE negotiation at all.

Troubleshooting already performed

  1. WAN connectivity

The FPT_PPP interface is UP and has the public IP:

183.80.161.10

The VPN interface is explicitly bound to FPT_PPP.

  1. WAN security policy

The existing system WAN-to-ZyWALL policy already allows:

  • IKE / UDP 500
  • NAT-T / UDP 4500
  • ESP
  • AH

We verified that the VPN connection attempts do not increase the security-policy drop counter.

  1. IKE/IPsec counters

IKE counters remain at zero during/after the connection attempt.

There is no IKE SA, half-open SA, or IPsec SA.

  1. DoS protection

IKE DoS protection is enabled, but:

  • half-open SA count = 0
  • init-limit-half-open = 0
  • no evidence that the client IP is blocked
  1. IP Reputation

IP Reputation is enabled, but the block list does not contain the client IP.

  1. Certificate

We initially used an older certificate.

We generated and tested a new RSA certificate:

RemoteAccess_VPN_RSA

The certificate is:

  • RSA 2048
  • SHA256
  • Server Authentication
  • Client Authentication
  • IKE Intermediate
  • SAN contains the public IP 183.80.161.10

After changing to this certificate, the USG FLEX was able to successfully generate/export the native Windows IKEv2 configuration ZIP.

However, the VPN connection problem remains.

  1. Authentication

We removed AD/Samba authentication from the troubleshooting path and changed the VPN authentication backend to a local USG FLEX user.

Current VPN user:

sonc

Therefore the current test does not depend on our Samba AD/LDAP configuration.

  1. VPN profile

The native Windows VPN profile generated by the USG FLEX was installed and tested.

The profile is configured as:

  • IKEv2
  • EAP
  • Split tunneling
  • Route: 10.8.1.0/24
  • AES256/SHA256
  • DH Group 14

Windows reports the VPN connection as terminated by the remote computer during the failed attempts.

  1. Packet capture

Packet captures show the client sending IKE_SA_INIT packets toward:

183.80.161.10 UDP/500

but no corresponding response from the USG FLEX was observed.

  1. Zyxel IPsec debug

We also used the official IPsec debug/trace mechanism:

cmd debug ipsec trace log

During the problematic attempts, there were no normal IKE negotiation events such as NET/IKE processing of the incoming IKE_SA_INIT request. Only periodic housekeeping messages such as:

[IKE] rechecking in 10s

were observed.

  1. System services

The IPsec/IKE related processes are running, including:

  • charon-systemd
  • radiusd
  • fptun-nfqd
  1. Fast-path resources

We checked fast-path CPU, memory and table utilization.

There is no indication of resource exhaustion.

The IPsec SA table is not exhausted.

Additional observation

The system log contains some fast-path messages such as:

[NFTABLE] Failed to get in_if_property for lo

and one:

[CONNTRACK] Failed to process packet for connection tracking for proto 6

However, we have not established a direct relationship between these messages and the IKEv2 problem.

Firmware

The device is currently running:

V1.39(ABWV.0)

We understand that V1.39 contains several VPN-related fixes, but we do not want to assume that the firmware is the cause without further evidence.

We would appreciate Zyxel engineering/support assistance in determining why the FLEX 200H is not processing the incoming IKE_SA_INIT packets.

Questions for Zyxel Support

  1. Why would the FLEX 200H receive/see IKEv2 traffic at the WAN interface but show:ike-init-in-req = 0and no IKE SA / half-open SA?
  2. Is there any internal service, process, fast-path component, IPsec subsystem, or configuration state that could prevent charon/strongSwan from receiving or processing UDP/500 traffic?
  3. Are there any known issues with IKEv2 Remote Access VPN on USG FLEX 200H running V1.39(ABWV.0)?
  4. Could the current V1.39 firmware or IPsec/IKE subsystem require a service restart or have a known state/configuration issue?
  5. Is there a recommended diagnostic command or procedure that can capture the IKE packet processing path from WAN interface -> fast-path -> IKE/charon?
  6. If necessary, can you review our configuration/system logs and determine whether the issue is related to the firmware or IPsec subsystem?

We can provide the following if required:

  • Configuration backup
  • Packet capture
  • IPsec debug output
  • System log
  • Screenshots of the VPN configuration
  • Firmware/version information

Please advise what additional diagnostic information you need from the device.

Thank you.