USG VPN tunnel for AVAYA phone
Hello all,
I am attempting to configure a USG VPN for use with an Avaya phone system. I have successfully built a PSK based tunnel that works with the Zyxel VPN client using IPSec, but have been unable to get an Avaya phone (model 9608) to connect using these settings. The phone is failing during the 'Exchanging Keys' configuration and the phone gives the failure reason as 'IKE Phase 1 No Response'.
My google-fu has turned up quite an array of configuration tweaks and changes that I have tried with no change to the outcome. None of the threads were related to the ZyWall series of devices so I decided to ask here.
I will be happy to post my configs and/or logs if anyone has any suggestions or questions to help with the configuration.
** I am looking for confirmation that someone has successfully used a USG VPN to connect to any VOIP hardphone and in specific with an Avaya of any model. **
Thank you in advance for your time and consideration.
------------------
Leo D.
I am attempting to configure a USG VPN for use with an Avaya phone system. I have successfully built a PSK based tunnel that works with the Zyxel VPN client using IPSec, but have been unable to get an Avaya phone (model 9608) to connect using these settings. The phone is failing during the 'Exchanging Keys' configuration and the phone gives the failure reason as 'IKE Phase 1 No Response'.
My google-fu has turned up quite an array of configuration tweaks and changes that I have tried with no change to the outcome. None of the threads were related to the ZyWall series of devices so I decided to ask here.
I will be happy to post my configs and/or logs if anyone has any suggestions or questions to help with the configuration.
** I am looking for confirmation that someone has successfully used a USG VPN to connect to any VOIP hardphone and in specific with an Avaya of any model. **
Thank you in advance for your time and consideration.
------------------
Leo D.
0
Comments
-
After google, Ayaya phone connect IPSec gateway with X-Auth and mode config.
https://downloads.avaya.com/css/P8/documents/100072456
So I think USG with 4.20 or above version can support that.
Here is an example CLI configuration of USG IPSec mode config,username test password test1234 user-type useraddress-object ANY_NETWORK 0.0.0.0/0address-object IPSEC_IP_POOL 10.10.98.1-10.10.98.20isakmp policy IPSEC_MODECONFpeer-ip 0.0.0.0 0.0.0.0local-ip interface wan1authentication pre-sharekeystring your-psk-heremode aggressivetransform-set aes128-shagroup2lifetime 86400peer-id type anylocal-id type fqdn your-usg-namexauth type server default user-id anyexitcrypto map IPSEC_MODECONFipsec-isakmp IPSEC_MODECONFencapsulation tunneltransform-set esp-aes128-shaset security-association lifetime seconds 28800set pfs nonescenario remote-access-serverlocal-policy ANY_NETWORKremote-policy anymode-config activatemode-config address-pool IPSEC_IP_POOLexitwrite0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight