<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN with Zyxel USG110 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92880#M10776</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Even with VPN Tunnel Sharing to "pair of hosts" didn't work. the discuss you share give some hints to solve this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After change IKE v2 to IKE v1 on&amp;nbsp;&amp;nbsp;Zyxel all tunnels get up and the traffic works fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once again, thank you very much.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2020 15:13:49 GMT</pubDate>
    <dc:creator>HS</dc:creator>
    <dc:date>2020-07-30T15:13:49Z</dc:date>
    <item>
      <title>VPN with Zyxel USG110</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92519#M10774</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we are facing some difficult to establish a IPSEC VPN&amp;nbsp; with&amp;nbsp;Zyxel USG110 and our Checkpoint R80.20.&lt;/P&gt;&lt;P&gt;We have 3 networks (encryption domain) on IPSEC VPN but it is random just one of the network is active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some point&amp;nbsp;Zyxel USG110 has just one of the 3 networks active and it is random.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we just configure one network works fine, but if we add one more network one of them will be down and it is&amp;nbsp; random.&lt;/P&gt;&lt;P&gt;Checkpoint logs we have just this reject:&lt;/P&gt;&lt;P&gt;IKE: Child SA exchange: Sending notification to peer: Invalid Key Exchange payload&lt;/P&gt;&lt;P&gt;IKE Category:&amp;nbsp;Reject Category&lt;/P&gt;&lt;P&gt;The source is from&amp;nbsp;Zyxel USG110 to our checkpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel management: "One VPN Tunnel per subnet pair" pair changed to&amp;nbsp;"One VPN Tunnel per gateway pair" . The behavior it's the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on a dump i get&amp;nbsp;NONESP-encap: isakmp: phase 2/others ? #36[]&lt;/P&gt;&lt;P&gt;looks like the traffic it is not being encapsulated ?&lt;/P&gt;&lt;P&gt;Do you have any idea what could be missing from Checkpoint configuration ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 12:21:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92519#M10774</guid>
      <dc:creator>HS</dc:creator>
      <dc:date>2020-07-27T12:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with Zyxel USG110</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92544#M10775</link>
      <description>&lt;P&gt;Try setting VPN Tunnel Sharing to "pair of hosts".&amp;nbsp; Does the VPN fail completely after a policy install and any existing tunnels are reset on both sides?&amp;nbsp; If so you have Phase 2 Proxy-ID/subnet issues which the Zyxel is very picky about, see here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/IKE-Failure-on-Site-to-site-IPSec-VPN-with-Zyxel-USG-open-for/m-p/86227" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/IKE-Failure-on-Site-to-site-IPSec-VPN-with-Zyxel-USG-open-for/m-p/86227&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 16:28:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92544#M10775</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-27T16:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with Zyxel USG110</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92880#M10776</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Even with VPN Tunnel Sharing to "pair of hosts" didn't work. the discuss you share give some hints to solve this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After change IKE v2 to IKE v1 on&amp;nbsp;&amp;nbsp;Zyxel all tunnels get up and the traffic works fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once again, thank you very much.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 15:13:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92880#M10776</guid>
      <dc:creator>HS</dc:creator>
      <dc:date>2020-07-30T15:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with Zyxel USG110</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92882#M10777</link>
      <description>&lt;P&gt;Yeah unfortunately interoperability between vendors is still pretty spotty with IKEv2, seen issues like this many many times.&amp;nbsp; It took IKEv1 seemingly about 10 years to work properly between all the vendors, so my advice when setting up an interoperable VPN is to give IKEv2 a shot, and if there are any problems do not hesitate to go back to IKEv1.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 15:25:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-Zyxel-USG110/m-p/92882#M10777</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-30T15:25:41Z</dc:date>
    </item>
  </channel>
</rss>

