Zyxel USG Flex 100HP Site2Site

fbw_user
fbw_user Posts: 3  Freshman Member
First Comment Friend Collector

Good day,

i do have a main network 192.168.99.x (Site A) which is connected via route based vpn IKEv2 to a remote network 192.168.100.x (Site B). The VPN connection is being established without any problems. After that i have tried to ping from both sites to the other and it works without any problems. But the SMB connection works only to site (B) and only sporadically. I have security policy on both sites being VPN - LAN, LAN-VPN. Site B is located behind an Speedport Hybrid Router where i have forwarded every possible port.

I have tried to decrease the MTU size for my WAN interfaces, but this did not help. With security policies being disabled, it does not work either.

Do you have any recommendations ?

Thank you very much in advance.

All Replies

  • fbw_user
    fbw_user Posts: 3  Freshman Member
    First Comment Friend Collector

    Good day,

    Thank you to everyone who took the time to review and consider my issue. I wanted to provide an update and close the discussion with the resolution I found.

    After analyzing the network traffic, I discovered a significant number of retransmissions occurring between the two sites. This pointed to potential fragmentation issues. Following this, I retested various MTU sizes for my VTI interface.

    By setting the MTU size to 1340 bytes, the SMB connection now works reliably across both sites.

    I apologize for any inconvenience caused and appreciate any time or effort you may have spent on this. Hopefully, this solution might help someone facing a similar problem in the future.

    Thank you again!

Service & License Help Center