
Chapter 44 Troubleshooting
ZyWALL 110/310/1100 Series User’s Guide
531
subnets. See
Asymmetrical Routes on page 268
and the chapter about interfaces for more
information.
I cannot set up an IPSec VPN tunnel to another device.
If the IPSec tunnel does not build properly, the problem is likely a configuration error at one of the
IPSec routers. Log into both ZyXEL IPSec routers and check the settings in each field methodically
and slowly. Make sure both the ZyWALL and remote IPSec router have the same security settings
for the VPN tunnel. It may help to display the settings for both routers side-by-side.
Here are some general suggestions. See also
.
• The system log can often help to identify a configuration problem.
• If you enable NAT traversal, the remote IPSec device must also have NAT traversal enabled.
• The ZyWALL and remote IPSec router must use the same authentication method to establish the
IKE SA.
• Both routers must use the same negotiation mode.
• Both routers must use the same encryption algorithm, authentication algorithm, and DH key
group.
• When using manual keys, the ZyWALL and remote IPSec router must use the same encryption
key and authentication key.
• When using pre-shared keys, the ZyWALL and the remote IPSec router must use the same pre-
shared key.
• The ZyWALL’s local and peer ID type and content must match the remote IPSec router’s peer and
local ID type and content, respectively.
• The ZyWALL and remote IPSec router must use the same active protocol.
• The ZyWALL and remote IPSec router must use the same encapsulation.
• The ZyWALL and remote IPSec router must use the same SPI.
• If the sites are/were previously connected using a leased line or ISDN router, physically
disconnect these devices from the network before testing your new VPN connection. The old
route may have been learnt by RIP and would take priority over the new VPN connection.
• To test whether or not a tunnel is working, ping from a computer at one site to a computer at the
other.
Before doing so, ensure that both computers have Internet access (via the IPSec routers).
• It is also helpful to have a way to look at the packets that are being sent and received by the
ZyWALL and remote IPSec router (for example, by using a packet sniffer).
Check the configuration for the following ZyWALL features.
• The ZyWALL does not put IPSec SAs in the routing table. You must create a policy route for each
VPN tunnel. See
.
• Make sure the To-ZyWALL firewall rules allow IPSec VPN traffic to the ZyWALL. IKE uses UDP port
500, AH uses IP protocol 51, and ESP uses IP protocol 50.
• The ZyWALL supports UDP port 500 and UDP port 4500 for NAT traversal. If you enable this,
make sure the To-ZyWALL firewall rules allow UDP port 4500 too.
Содержание ZyWALL 110 Series
Страница 16: ...ZyWALL 110 310 1100 Series User s Guide 16...
Страница 32: ...Chapter 1 Introduction ZyWALL 110 310 1100 Series User s Guide 32...
Страница 42: ...Chapter 3 Hardware Introduction ZyWALL 110 310 1100 Series User s Guide 42...
Страница 68: ...Chapter 4 Quick Setup Wizards ZyWALL 110 310 1100 Series User s Guide 68...
Страница 83: ...Chapter 6 Monitor ZyWALL 110 310 1100 Series User s Guide 83 Figure 60 Monitor System Status Interface Status...
Страница 128: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 128 Figure 83 Configuration Network Interface PPP Add...
Страница 135: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 135 Figure 85 Configuration Network Interface Cellular Add...
Страница 176: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 176...
Страница 186: ...Chapter 8 Trunk ZyWALL 110 310 1100 Series User s Guide 186...
Страница 210: ...Chapter 10 Routing Protocols ZyWALL 110 310 1100 Series User s Guide 210...
Страница 220: ...Chapter 12 DDNS ZyWALL 110 310 1100 Series User s Guide 220...
Страница 228: ...Chapter 13 NAT ZyWALL 110 310 1100 Series User s Guide 228...
Страница 240: ...Chapter 15 ALG ZyWALL 110 310 1100 Series User s Guide 240...
Страница 246: ...Chapter 16 IP MAC Binding ZyWALL 110 310 1100 Series User s Guide 246...
Страница 263: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 263...
Страница 264: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 264...
Страница 270: ...Chapter 19 Firewall ZyWALL 110 310 1100 Series User s Guide 270 Figure 163 Configuration Firewall...
Страница 296: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 296 Figure 182 Configuration VPN IPSec VPN VPN Gateway Edit...
Страница 316: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 316...
Страница 340: ...Chapter 22 SSL User Screens ZyWALL 110 310 1100 Series User s Guide 340...
Страница 442: ...Chapter 36 DHCPv6 ZyWALL 110 310 1100 Series User s Guide 442...
Страница 540: ...Appendix A Legal Information ZyWALL 110 310 1100 Series User s Guide 540...
Страница 558: ...Index ZyWALL 110 310 1100 Series User s Guide 558...
Страница 559: ...Index ZyWALL 110 310 1100 Series User s Guide 559...
Страница 560: ...Index ZyWALL 110 310 1100 Series User s Guide 560...
Страница 561: ...Index ZyWALL 110 310 1100 Series User s Guide 561...
Страница 562: ...Index ZyWALL 110 310 1100 Series User s Guide 562...