VPN2S not blocking by default UDP 500

PeterUK
PeterUK Posts: 3,331  Guru Member
100 Answers 2500 Comments Friend Collector Seventh Anniversary
edited April 2021 in Security

With no L2TP VPN or IPsec VPN on the WAN only a IPsec VPN connecting to the LAN at 192.168.255.202 for Site-to-site.

Sending a Identity Protection (Main Mode) UDP 500 to the WAN replays with Informational by the VPN2S.

Workaround make firewall rule to drop from WAN to router.


Comments

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,206  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Hi @PeterUK

     

    There are some points need to clarify:

    (1)   What is your test topology? Could you illustrate it?

    (2)   What is the symptom? and test procedure? Could you describe them more detailed?

    (3)   Could you provide your configuration file(Maintenance > Backup / Restore > Backup) with and without workaround solution via private message to me?



    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

  • PeterUK
    PeterUK Posts: 3,331  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    VPN2S to WAN and make a windows 10 VPN L2TP connection over 4G to WAN of the VPN2S.

    Send you a packet capture of the symptom and what you need to send to WAN on VPN2S.


Security Highlight