G
ATEWAY
C
ONTROLLER
S
ERIES
U
SER
M
ANUAL
2011, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P
AGE
90
OF
124
VPN IPSec Troubleshooting
The focus of the VPN IPSec standard is to ensure security, not compatibility or ease
of use. The protocol is unforgiving of configuration errors. The VPN connection will
generally be refused if something does not match. In trying to get two gateways to
connect triple check all of the settings including VPN ID, Protocol, and Key
Timeouts. All Phase 1 and Phase 2 settings much match, of course. Check the
VPN Log to see if there are any obvious errors. If your first choice of Encryption
and Authentication will not connect please try all of the other options, and use the
Additional Proposals option.
As a last resort, try manual keys. This does not make the connection much less
secure in itself, but you have to protect the keys and change them like any other
pre-shared key. However, figuring out the actual HEX key sent by different VPN
Gateway manufacturers may also be a headache.