Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HS
Contributor

VPN with Zyxel USG110

Hi,

we are facing some difficult to establish a IPSEC VPN  with Zyxel USG110 and our Checkpoint R80.20.

We have 3 networks (encryption domain) on IPSEC VPN but it is random just one of the network is active. 

For some point Zyxel USG110 has just one of the 3 networks active and it is random. 

If we just configure one network works fine, but if we add one more network one of them will be down and it is  random.

Checkpoint logs we have just this reject:

IKE: Child SA exchange: Sending notification to peer: Invalid Key Exchange payload

IKE Category: Reject Category

The source is from Zyxel USG110 to our checkpoint. 

Tunnel management: "One VPN Tunnel per subnet pair" pair changed to "One VPN Tunnel per gateway pair" . The behavior it's the same.

 

on a dump i get NONESP-encap: isakmp: phase 2/others ? #36[]

looks like the traffic it is not being encapsulated ?

Do you have any idea what could be missing from Checkpoint configuration ?

0 Kudos
3 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events