VPN2S not blocking by default UDP 500

Options
PeterUK
PeterUK Posts: 2,724  Guru Member
First Anniversary 10 Comments Friend Collector First Answer
edited April 2021 in Security

With no L2TP VPN or IPsec VPN on the WAN only a IPsec VPN connecting to the LAN at 192.168.255.202 for Site-to-site.

Sending a Identity Protection (Main Mode) UDP 500 to the WAN replays with Informational by the VPN2S.

Workaround make firewall rule to drop from WAN to router.


Comments

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,066  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @PeterUK

     

    There are some points need to clarify:

    (1)   What is your test topology? Could you illustrate it?

    (2)   What is the symptom? and test procedure? Could you describe them more detailed?

    (3)   Could you provide your configuration file(Maintenance > Backup / Restore > Backup) with and without workaround solution via private message to me?


  • PeterUK
    PeterUK Posts: 2,724  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    VPN2S to WAN and make a windows 10 VPN L2TP connection over 4G to WAN of the VPN2S.

    Send you a packet capture of the symptom and what you need to send to WAN on VPN2S.


Security Highlight