Comments
-
It seems a known limitation on ATP model.
-
ZYXEL firewall uses a self-signed certificate, so you need to install a valid 3rd party certificate with full chain to the firewall. In this post, you can find how to import root certificate, intermediate certificates and end-entity certificate to the firewall.
-
Would you like to authenticate the wireless users that connect to the ATP500 using WPA2-Enterprise (802.1X)? If so, I think you should configure RADIUS in AAA Server instead of AD.
-
Need to enable IGMP on the interfaces. Here is an example. https://support.zyxel.eu/hc/en-us/articles/360004093659-IPTV-with-multicast-and-IGMP-USG-ATP-VPN
-
Both the browser and website support HSTS. Here is a similar post.
-
Which secuextender version is installed? IPSec_SSL_VPN_7.7.40.019 for Windows or IPSec_SSL_VPN_3.2.4.19 for macos?
-
Seems a known issue on macOS 14 Sonoma. I tired to set a value smaller than 1440 in phase 2 SA life time but macOS 14 still disconnects exactly after 24 minutes. https://github.com/feedback-assistant/reports/issues/448 https://forums.developer.apple.com/forums/thread/742731
-
What's the firmware version on USG2200-VPN? Is the AP managed by USG2200-VPN? When the wifi client has no internet connection, try to ping the gateway IP from the wifi client and ping any external IP from the USG2200-VPN respectively to clarify the issue.
-
You can check if the connectivity check is enabled on ge2_ppp.
-
You can find a configuration guide in the DPF file "How to configure the VPN settings if two sites are using the same network subnet" in this discussion.
-
It seems this function should be handled by switch, not the firewall.
-
Because the AD is at the remote site over IPSec VPN, try to configure a static route on USG Flex 700. Destination IP: 192.168.20.0 Subnet Mask: 255.255.254.0 Interface: Select the lan interface which is the local policy configured for Site-to-Site VPN
-
Could you describe the way you access caldav? Is it a caldav server in lan and you'd like to access it through NAT from wan(DDNS)?
-
Here are some examples using strongswan on Linux to establish vpn. I hope these will help. https://community.zyxel.com/en/discussion/15678/usg-flex-200-no-proposal-error-with-strongswan https://community.zyxel.com/en/discussion/9890/i-can-connect-from-windows-10-but-cant-from-linux
-
Seems CA is invalid. Do you select the default certificate?