VPN to Flex100H is driving me crazy

2»

All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,103  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @amateur_netops

    Please try adjusting the LAN interface MTU size to 1300 on both firewalls to see if it helps with your issue.

    If the issue persists, could you capture packets on the server end for both the USG FLEX 100H and the USG FLEX 200H traffic?

    Kay

    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community

  • amateur_netops
    amateur_netops Posts: 12  Freshman Member
    First Comment
    Answer ✓

    I ended up rebuilding the 100H after a factory reset - made all VPNS IKE2 now - still didn't work. Set MTU to 1300 - now works.

    Thank you!

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,103  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @amateur_netops

    I'm glad to hear it's working! The root cause may be related to packet fragmentation. VPNs encapsulate data into larger packets, which increases their size. When the MTU is set too high, packets might exceed the size supported by network devices or along the internet path, causing fragmentation or packet drops.

    By adjusting the MTU, you've helped the packets fit within network limits, reducing fragmentation and allowing VPN traffic to flow more smoothly.

    Kay

    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community

Security Highlight