VPN Configuration on Zyxel USG FLEX 700

Posts: 14  Freshman Member
First Comment First Anniversary
edited February 2024 in Security

I am configuring and IPSec VPN on this router and each time, I get this error in the logs.

The highlighted line is where I am having the issue. That tunnel is another VPN I have configured on the router that is working for something else. I am not sure why this new VPN is trying to use that tunnel for authentication. It has a policy mismatch, because it is configured different because it is used for something else.

Here is the correct gateway.

Here is the VPN using that gateway.

So what is causing it to try to authenticate with this Tunnel?

UPDATE: If I change my phase 2 encapsulation setting to "transport" I get this error:

Firmware version: V5.37(ABWD.1)

Welcome!

It looks like you're new here. If you want to get involved, click on this button!
«1

All Replies

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Change Local policy to 0.0.0.0

  • Posts: 14  Freshman Member
    First Comment First Anniversary

    No luck. I get the same error. Phase 1 works no problem, but it seems to continue to try and authenticate phase 2 with the wrong VPN.

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    If you have other IKEv1 tunnels on the same interface that can cause problems

  • Posts: 14  Freshman Member
    First Comment First Anniversary

    So, if I need multiple VPNs what is the solution?

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Not sure I think Phase 1 local ID and Peer ID type might be needed

    or you can try having IKEv2 for tunnels site to site and IKEv1 for Remote Access (Server Role)

  • Posts: 14  Freshman Member
    First Comment First Anniversary

    I wish I could figure out what exactly these errors mean. Phase 1 seems to work fine.

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Have you setup L2TP VPN for the server role?

  • Posts: 14  Freshman Member
    First Comment First Anniversary

    This?

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    So testing here Phase 1 local ID and Peer ID type don't allow more then one type of VPN on the same interface but if you do site to site as IKEv2 with a IKEv1 server role that works

  • Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    also on the same interface with IKEv1 you can have site to site by Pre-Shared Key and  server role by Certificate

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!