Unable to Duplicate Working USG500H-ATP200 VPN for Add'l Site
Freshman Member
Fairly new USG500H is not connecting to a remote ATP200 over site-to-site VPN. Both devices are being managed via NCC. The ATP200 is a fresh enrollee and had to be reconfigured as a result.
On the USG500H, I have duplicated a working manual-link VPN settings (using the gateway/remote address of the remote site) and it will not even allow me to save the config from NCC. I had to use the local web interface to duplicate this config.
The working VPN remote device not enrolled in NCC. I would like to have all devices enrolled in NCC.
Working USG500H Main VPN config:
IKEv2
Police-based
ge2 (WAN)
Peer address is correct
Zone = IPSec_VPN
PSK
Adv Phase 1:
86400
AES128/SHA1
DH2, DH14
Phase 2:
Local = same as primary LAN 192.168.0.0/22 (saved as a different object)
Remote = same as remote LAN1 172.19.10.1/24 (saved as an object)
Working Remote ATP200 (not enrolled in Nebula) config:
Nailed-up
NetBIOS over IPSec enabled
MSS adjustment = Auto
Narrowed
App Scenario: Site-to-Site
VPN Gateway = Main site public IP
Local policy - same as remote site primary LAN 172.20.10.0/24
Remote policy: same as main site primary LAN 192.168.0.0/22
Phase 2: ESP, Tunnel, AES128/SHA1, DH2, DH14
Zone: IPSec_VPN
Practically none of the settings on the non-NCC ATP200 are available on the NCC-enrolled ATP200.
So what's the trick here? Maybe I expected too much from NCC/cloud management altogether? Would I be better served to drive to the remote site, factory reset the ATP200, configure it from the local web interface, and be happy that it works?
PS: Sure would be nice if the config backup it created on enrollment could be applied to the device after enrolled.
All Replies
-
Do you mean these devices can connect site-to-site VPN when they did not enrollee in NCC? And have issue when both add to Nebula? If it is this case, please help to enable Zyxel support access and share the organization's name and site's name with us to check.
Additionally, which firmware version is your ATP and USG FLEX H running?
Zyxel Melen0 -
Remote admin invite sent.
0 -
More info:
Site-to-Site VPN #1: USG 500H to ATP200 (non-NCC) VPN is up and working.
Site-to-Site VPN #2: was working on ATP200-ATP200 prior to upgrading Main site to USG500H. Decided to go the NCC route with this second site to minimize travel to that location.
Tried to duplicate VPN #1 config for VPN #2 but the difference between local web interface settings and NCC settings is significant and seems to offer greatly diminished configuration options.
I will send you a message with org+site details.
0 -
Might be easier to firewall in to local from remote and then config it without NCC?
0 -
First, you can enable Nebula site-to-site VPN > Nebula SD-VPN. This reduces many configuration steps to create the site-to-site VPN
Reference FAQ:
Nebula VPN for H Series Firewalls — Zyxel Community
Second, your VPN setting has some misconfiguration:
- USG FLEX H site is using different Proposal in Phase 1 & 2 with ATP site.
- USG FLEX H site is using incorrect local subnet object in Phase 2 setting with ATP site VPN setting. You need to correct the address object you set on USG FLEX H site VPN setting.
- ATP site is using different Phase 2 PFS group with USG FLEX H site.
Please change these configurations first.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Zyxel Employee
Guru Member