USG60 <> USG200 Site2Site VPN stopped working after WAN IP change


All Replies

  • stephan
    stephan Posts: 31  Freshman Member
    First Anniversary 10 Comments Friend Collector
    Answer ✓

    Okay these seem to have been transient issues.

    I restarted the USSG60 once again between my last post and now (it was restarted before my last post) without any configuration changes and it works now. Key handshake runs on USP4500 now as expected. All other stages of the VPN work.

    I think my USG 60 at the branch office had some latent borked configuration. After the first reboot, some changes from the past few months (without reboots) were gone. Nothing too major, but odd nevertheless. Good thing we are switching to a newer USG200 here soon.

    Special thanks to PeterUK who brought me on the right track.

  • PeterUK
    PeterUK Posts: 3,000 ✭✭✭✭✭
    Community MVP First Anniversary 10 Comments Friend Collector
    edited April 2023 Answer ✓

    No putting one behind  NAT will use port 4500 as the tunnel port 500 is used for exchange keys

    Can you check by packet capture on the USG you are sending and receiving either 4500 or protocol 50 when sending ping

    its also possible your ISP beyond support knows nothing of the block and just tell you ESP is not blocked

    Edit: I see its all working😁

Security Highlight