Hi,
we are facing some difficult to establish a IPSEC VPN with Zyxel USG110 and our Checkpoint R80.20.
We have 3 networks (encryption domain) on IPSEC VPN but it is random just one of the network is active.
For some point Zyxel USG110 has just one of the 3 networks active and it is random.
If we just configure one network works fine, but if we add one more network one of them will be down and it is random.
Checkpoint logs we have just this reject:
IKE: Child SA exchange: Sending notification to peer: Invalid Key Exchange payload
IKE Category: Reject Category
The source is from Zyxel USG110 to our checkpoint.
Tunnel management: "One VPN Tunnel per subnet pair" pair changed to "One VPN Tunnel per gateway pair" . The behavior it's the same.
on a dump i get NONESP-encap: isakmp: phase 2/others ? #36[]
looks like the traffic it is not being encapsulated ?
Do you have any idea what could be missing from Checkpoint configuration ?