VPN2S not blocking by default UDP 500

Options
PeterUK
PeterUK Posts: 4,344 image  Guru Member
250 Answers 2500 Comments Friend Collector Eighth Anniversary
edited April 2021 in Security

With no L2TP VPN or IPsec VPN on the WAN only a IPsec VPN connecting to the LAN at 192.168.255.202 for Site-to-site.

Sending a Identity Protection (Main Mode) UDP 500 to the WAN replays with Informational by the VPN2S.

Workaround make firewall rule to drop from WAN to router.


Comments

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,359 image  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fifth Anniversary

    Hi @PeterUK

     

    There are some points need to clarify:

    (1)   What is your test topology? Could you illustrate it?

    (2)   What is the symptom? and test procedure? Could you describe them more detailed?

    (3)   Could you provide your configuration file(Maintenance > Backup / Restore > Backup) with and without workaround solution via private message to me?


  • PeterUK
    PeterUK Posts: 4,344 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    VPN2S to WAN and make a windows 10 VPN L2TP connection over 4G to WAN of the VPN2S.

    Send you a packet capture of the symptom and what you need to send to WAN on VPN2S.