Site-to-site VPN between Zywall 110 and MS Azure

Options
EricLogsdon
EricLogsdon Posts: 8 image  Freshman Member
First Answer First Comment Sixth Anniversary
edited September 2023 in Security

I am setting up a Site-to-Site VPN between my small office and MS Azure. The office network is behind a NAT in the Zywall 110 since we have multiple public IP addresses for some outward facing servers. I have seen references to Policy Based and Route based VPN. Which is better?

[Update]

I used the Quick Setup wizard, which generated a Policy Based Site-to-Site VPN. The MS Azure connection stays in a "connecting" status and the Zywall never goes to connected status. If I click the Connect button for the connection, it times out. I am guessing something isn't in sync between the two configuration, but I don't see what it is.

Here is the Zywall configuration:

Gateway

image.png

Connection:

image.png

The Azure settings are:

Azure Vnet Address space:

image.png

Vnet subnets:

image.png

Vnet Gateway:

image.png

Local Net Gateway:

image.png

Connection:

image.png

Any wisdom would be appreciated.

Eric

Accepted Solution

  • Zyxel_James
    Zyxel_James Posts: 788 image  Guru Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers
    Answer ✓

    @EricLogsdon

    The logs show "Phase 1 Peer ID mismatch" and "No proposal chosen", please check if the phase 1/2 algorithms have corresponded, and the Local/Peer ID seems incorrect too. Please show the encrypted algorithms of phase1/2.

    Moreover, is your firewall behind NAT?

All Replies