CHS  Master Member

Comments

  • I suggest giving these steps provided by ZyXEL a try. They have been successful for me in upgrading the firmware.
  • I suggest giving these steps provided by ZyXEL a try. They have been successful for me in upgrading the firmware.
  • I suggest giving these steps provided by ZyXEL a try. They have been successful for me in upgrading the firmware.
    in USG60 FW Upgrade Comment by CHS May 26
  • I suggest upgrading the firmware to the latest version as a first step. After the upgrade, carefully monitor the system to determine if the issue still persists.
  • You may ensure that firmware version on your USG310 is updated and newer than the previous one. This is important as certain commands may not be available in older versions.
  • I'd suggest trying out the 5.36(ABUI.1) firmware for your device. There have been positive test results reported by users in other threads. It might be beneficial for your case as well.
  • In your trunk settings, there's an option to create a "User Configured Trunk". This feature should be suitable for your scenario.
  • Since your logs are showing "no Proposal chosen," it's likely that there's a mismatch in the Phase 1 or Phase 2 settings between the USG100 and the Flex 200. Ensure that both sides are using the same settings for Phase 1 and Phase 2 negotiations. This includes encryption, hash, Diffie-Hellman Group, and lifetime settings.
    in IPSec-VPN problems Comment by CHS May 16
  • On remote office, You can add all of your intranet IP segments as a group abject first. And add policy route to route traffic to main office. e.g. Source: IP Group, Destination: Any, Next Hop: VPN tunnel Of course, you have to add the same rule to route traffic back to remote office. e.g. Source: Any, Destination: IP…
  • One possible solution to this issue is to configure a "new IP pool" for remote VPN clients on the USG110, and then ensure that the ERP site is configured to route traffic from this "new IP pool" back to the local site. You can refer to the article which provides detailed instructions on how to forward traffic to a branch…
  • You can have a try to setup DNS Server. (e.g. 8.8.8.8)
  • You can have a try Server Name & URL in DDNS within user custom setting. Server: dyndns.strato.com URL: /nic/update?
    in Strato Dyndns Comment by CHS April 6
  • You can try 'Fast Forwarding' on the USG60, which allows traffic to pass without content checking. (Configuration > System > Advanced > Fast Forwarding)
  • Are there many users did not authorised by Web Authentication function?
  • The default firewall policies allow traffic to and from the IPSec VPN Tunnel because the latest rule blocks all traffic "From Any to Any". Therefore, the rules you mentioned should not cause any problems. You can check if any policy route rules are affecting your VPN traffic.
Avatar