usg 1000 vpn 16015 error
Question ,
i have 3 USG 1000 firewalls first one has firmware 3.00 and the other has 3.30
i setup the first firewall , this one is online and running, the VPN is working fine !
the other 2 , i restored the settings from the first firewall, ( these other 2 are offline )
if i want to connect the default VPN, it gives an error ( 16015 dial a dynamic tunnel has failed crypto )
is this because it,s not connected to the internet, or is this firmware related ?
thanks
1
Comments
-
This message looks like that the setup on the client or the proposal for tunnel did not match the server's.
Are the ip ranges and encryption method identical on the both sides?0 -
Hello Kriszty,
G'day
For the L2TP connection, you should initiate the session from client side not server side, because the peer security gateway(client) is dynamic address (0.0.0.0)which means USG does not know which client can be established tunnel.
This is why you press connect button, it will show this error message.
To avoid this issue occur, once again please make sure to initiate the L2TP session on Client side not server side.
If the issue still happen, please share the configuration via private message, and share the screenshot of log message.
Thanks
BR,
Charlie
0 -
so basicly, if i connect it to the internet ( online ), it should work ? , i will try it this weekend, thanks for the replies
0 -
Hello Kriszty,
Does the issue disappear or still occur?
Charlie0 -
hi Charlie, yes it works now ...
but another question, how to setup my zywall so only the vpn is made ( wich can access the lan network ) but for internet using his own internet connection. Now if a client makes a vpn it uses the zywall internet connection. i can disable the zywall internet access, but then the client can not use his own internet connection, is this firewall related or routing ?
0 -
this is the routing screen
0 -
this is the firewall rules
0 -
this is my setup, i can connect to the vpn and access my external lan , but i want to use my own internet...not the zywall internet
0 -
When you establish L2TP VPN to USG, the all traffic will be redirect to tunnel.
If you want to access internet also l2TP enable, the only way is that access internet via USG.
However, if you dont want to use USG's internet connection, just disable L2TP tunnel, and you can use own internet connection.0 -
Hi Jeremy, should i remove the last line in the routing ?
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 145 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 239 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight