VPN2S not blocking by default UDP 500

PeterUK Posts: 3,645  Guru Member
100 Answers 2500 Comments Friend Collector Seventh Anniversary
edited April 2021 in Security

With no L2TP VPN or IPsec VPN on the WAN only a IPsec VPN connecting to the LAN at for Site-to-site.

Sending a Identity Protection (Main Mode) UDP 500 to the WAN replays with Informational by the VPN2S.

Workaround make firewall rule to drop from WAN to router.


  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,311  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Hi @PeterUK


    There are some points need to clarify:

    (1)   What is your test topology? Could you illustrate it?

    (2)   What is the symptom? and test procedure? Could you describe them more detailed?

    (3)   Could you provide your configuration file(Maintenance > Backup / Restore > Backup) with and without workaround solution via private message to me?

  • PeterUK
    PeterUK Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    VPN2S to WAN and make a windows 10 VPN L2TP connection over 4G to WAN of the VPN2S.

    Send you a packet capture of the symptom and what you need to send to WAN on VPN2S.