connection vpn L2TP on local network work, but not by internet, dmz is OK on modem to USG
ptibonhomme
Posts: 12
in Security
Hello,
i try little to little to configure my vpn installation.
today, my vpn work on local network, so i test ton enter in my vpn by other connection internet, but i have errors :
i try little to little to configure my vpn installation.
today, my vpn work on local network, so i test ton enter in my vpn by other connection internet, but i have errors :
I don't understand why there are errors between phase 1 and 2 when it works locally
Thanks for your help
Thanks for your help
0
All Replies
-
Hi @ptibonhomme
You can make sure "My Address" setting of VPN phase 1 is configured as "0.0.0.0".
And also enter CLI command to unlock VPN incoming restriction. After applying configuration, reboot is required.
Router(config)# vpn-interface-restriction deactivate
0 -
Thanks for reply, i changer setting on the USG20, but the problem is same, the vpn is working for acces by lan but not by internet, always the same error on IKE log.
little question : in the method configuration client to site by L2TP on the zyxel site , no say to open restrisction on the cli of USG20.0 -
for the " my adresse " of phase 1 ( 0.0.0.0 ) i must have the same adresse on phase 2 ? or i keep " interface ip" ?0
-
Set both phase 1 local policy and phase 2 Domain Name / IPv4 to 0.0.0.0
Check your firewall rules have from WAN to Zywall and from zone IPSec_VPN to Zywall with services ESP,IKE,L2TP-UDP and NATT0 -
hello , I tried with your settings : still no connection
i show you my settings
Phase 1 :
phase 2
the rules
the log
i confirm , with this settings , the client VPN is connected if i am on a local network, the problem appears when i try to connect by internet .
thanks for you help, if you have an idea of the resolution0 -
Is your WAN by Ethernet without PPP? As that might be the issue.
Are you able will changes to get the VPN to work over the internet at all?
Maybe the phase 1 and phase 2 have the encryption/authentication set to high?
0 -
Hello, i modified setting for connection :
and i think the encryption is not to high
0 -
….or maybe the encryption/authentication is not high enough?
For phase 1 in order
3DES SHA 1
AES128 SHA1
key group DH2
For phase 2 in order
AES256 SHA1
AES128 SHA1
3DES SHA1
PFS none
0 -
i changed settings but not possible to connect , i show you the log
0 -
Does the USG have the WAN IP and not behind NAT?0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight