IPSec VPN Setup

Options
bermurray
bermurray Posts: 3 image  Freshman Member
First Comment Fourth Anniversary

I have a FLEX 200H that I am trying to setup IPsec VPN on. For the life of me cannot get it to work. I am have a old FLEX 200 and it was simple. Now have my options are gone.

I am trying to set it up inside the network of the FLEX 200 so that it is read when I do cut over with minimal down time.

I also use the web interface rather than Nebula since Nebula takes even more options away.

Does anyone have a nice knowledge base article that step-by-step sets up the IPsec VPN that does not use nebula? I cannot find what I need to make this work.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @bermurray

    You may check our handbook to setup the IPSec VPN first.

    USG FLEX H handbook

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 3
    Options

    Its made easy with VPN Configuration Script Download to get the client up and running when the VPN is setup.

    So first you need to know if you got inbound traffic support for UDP 4500, 500 and ESP and if your FLEX 200H gets the WAN IP because you said you have a older FLEX200 your likely ready for this just that the layout is different and maybe you used a non Certificate setup? which needs to be installed on the client device by the Script and by IP or Domain name? I recommend by Domain name get one by noip or IONOS and setup DDNS on the FLEX.

    so better way to setup the VPN to every port and for it to work in most cases is:

    VPN Server Address

    Type IP address

    IP address 0.0.0.0

    NAT traversal Custom IP or Domain name

    your Domain name

    Then disable and enable VPN if set for Certificate for VPN Validation set to auto gives you a self signed but you can choose Trusted Certificate to go with your Domain name note that the Script does not installed intermediate Certificate.

  • bermurray
    bermurray Posts: 3 image  Freshman Member
    First Comment Fourth Anniversary
    edited August 4
    Options

    I have static IP for my WAN and we do not use a Domain.

    I have setup my users and passwords (I will worry about MFA once this works) and download and use the script. This script also includes the certificate which I also install on the client machine.

    So my Setup looks like this:

    VPN Server Address: WAN static IP address

    NAT traversal Custom IP or Domain name:

    WAN static IP address.

    Is that wrong?

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 4
    Options

    the VPN Server Address: WAN static IP address

    only works if the FLEX interface has the WAN IP directly not like 192.168.0.2 or 10.0.0.2

    but might be worth trying 0.0.0.0