Vpn IpSec Ike V2 and ISP policies
Hi,
I have several customers using the windows ipsec ike2 vpn client to have their employees connect remotely.
Lately some users have complained that they are unable to connect due to the policies of the home ISP (In italy Eolo, Wind3, Iliad and i fear many other...)
In these cases, when the user tries to log on, connection goes in error and nothing appears on the ATP / USG logs.
Connection with hotspot on their business mobile is ok.
Has anyone had similar experiences, and found a viable solution?
Thank in advance
Fred
All Replies
-
Do you mean when connect vpn through mobile network to the ATP/USG, it works. However, it doesn't work if connect via home ISP line(PPPoE,IPoE, Cable modem, lease line…etc) ??
If so, can try to adjust the MTU size and see if packets were dropped due to packet oversized since you didn't see any log on ATP/USG which means it may not receive those vpn related packets
0 -
Hi,
yes, VPN throught their business mobile works, throught home isp … it depends on wich provider.
However: they don't use ssl vpn client but the windows embedded ipsec client.
MTU size is 1400
HTE Vodafone is IKE2 IPSec
Eth 5 is the virtual adapter for the Secuextender SSL
Fred
0 -
Hello @Fred_77
Since the device didn't have any logs, I suspect the device even didn't receive the VPN packets. It could be blocked by the home ISP router, please check if it allows VPN through the router firewall.0 -
Hi @Zyxel_James
that's exactly the point.
We can't configure every employee's home router. Not to mention that "domestic contracts" are a jungle and everyone is free to change provider at any time. My question was just whether anyone has come up with a solution that works regardless of the router.
0 -
In my opinion, it must be investigated between the employee's PC and the home router since it only connects failed when connecting to the home router.
We can narrow down the root cause first, then figure out the best solution for the employees.Except for the test I mentioned previously, could you conduct the mtupath test?
Please refer to the screenshot, and change the IP address to the VPN gateway Address.
mtupath.exe download link0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight