VPN Connection Issue

Fred_77
Fred_77 Posts: 126  Ally Member
5 Answers First Comment Friend Collector Fourth Anniversary

Hi all,

I'm wandering around a client-to-site VPN access issue.
Scenario: HQ USG310 (will be be replaced with 500H) with IKE2 with cert. client-to-site VPN and about 40 remote clients.
Some of them have strange connection issues "seemingly" related to the internet connection.
I took a couple of laptops and phones from the customer site to do some lab tests and now on my desk i have:
* Laptop1 (win11)
* Laptop2 (win10)
* Mobile Phone1
* Mobile Phone2 (they use the same mobile operator and same configuration APN,etc..)
* Lab's internet connection.

The customer complains about errors during vpn connection in certain conditions. Below are some tests that I have done in the lab and at the customer's home.

HTE VPN.png

In any condition, ports on USG are reachable and open

HTE VPN2.png

and this is what I see on the usg log

From the logs it seems evident that when the connection is not established, all traffic on the 4500 is absent. I wondered if it was the mobile operator or the device that was blocking this traffic, but the answer is no. In fact, the other laptop connected to the same mobile phone (at the same time) has no problem.

I was forgetting: I use the native windows vpn client and the error is: "Unable to establish connection between the computer and the VPN server. The remote server is not responding...."

Any suggestions are welcome.

Thanks in advance

Lorenzo

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,067  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @Fred_77 ,

    Since multiple clients are successfully establishing VPN connections, the firewall configuration appears to be correct.

    To troubleshoot the problematic clients (marked with X signal in red circle), please capture network packets on the WAN of firewall when these clients attempt to establish VPN connections and share the captures with us.

    image.png
  • Fred_77
    Fred_77 Posts: 126  Ally Member
    5 Answers First Comment Friend Collector Fourth Anniversary

    Hi @Zyxel_Judy

    captured files sent via PM

    Lorenzo

  • PeterUK
    PeterUK Posts: 3,727  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Maybe change DNS on them devices reboot and see if that works.

  • Fred_77
    Fred_77 Posts: 126  Ally Member
    5 Answers First Comment Friend Collector Fourth Anniversary

    HI @PeterUK,

    Thanks for your reply, I had already tried this without success.

    Zyxel staff is investigating

    Lorenzo

  • PeterUK
    PeterUK Posts: 3,727  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    It is likely one of two things 1 the customer ISP/router blocks VPN and/or 2 the ISP router may allow 1 VPN but not SNAT source port to allow more then one VPN connection