L2PT - USG60

DavidPr
DavidPr Posts: 2
First Comment
 Freshman Member
edited April 2021 in Security
Hi,

I have a problem with using L2TP...If I try connect directly to WAN port (pc->usg60->local LAN), l2tp correctly make connection. But, if i try used local ISP ( ISP router board->usg60->local LAN) l2pt connection say:

Connect by ISP:


Successful L2PT by directly connect:

I dont know, where is problem..

Thank you

David

All Replies

  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034
    50 Answers 500 Comments Friend Collector Fourth Anniversary
     Guru Member

    Hello DavidPr,
    According the pictures you shared, 
    it displays Phase 2 local policy mismatch, so make sure the VPN policy on both site (ISP’s router and USG)are the same first.
    Charlie

  • DavidPr
    DavidPr Posts: 2
    First Comment
     Freshman Member
    SOLVED:

    Problem was on the side ISP, IPsec dont like dstnat 1:1 for public IP.

Security Highlight