Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HS
Contributor

VPN with Zyxel USG110

Hi,

we are facing some difficult to establish a IPSEC VPN  with Zyxel USG110 and our Checkpoint R80.20.

We have 3 networks (encryption domain) on IPSEC VPN but it is random just one of the network is active. 

For some point Zyxel USG110 has just one of the 3 networks active and it is random. 

If we just configure one network works fine, but if we add one more network one of them will be down and it is  random.

Checkpoint logs we have just this reject:

IKE: Child SA exchange: Sending notification to peer: Invalid Key Exchange payload

IKE Category: Reject Category

The source is from Zyxel USG110 to our checkpoint. 

Tunnel management: "One VPN Tunnel per subnet pair" pair changed to "One VPN Tunnel per gateway pair" . The behavior it's the same.

 

on a dump i get NONESP-encap: isakmp: phase 2/others ? #36[]

looks like the traffic it is not being encapsulated ?

Do you have any idea what could be missing from Checkpoint configuration ?

0 Kudos
3 Replies
Timothy_Hall
Champion
Champion

Try setting VPN Tunnel Sharing to "pair of hosts".  Does the VPN fail completely after a policy install and any existing tunnels are reset on both sides?  If so you have Phase 2 Proxy-ID/subnet issues which the Zyxel is very picky about, see here:

https://community.checkpoint.com/t5/General-Topics/IKE-Failure-on-Site-to-site-IPSec-VPN-with-Zyxel-...

 

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
HS
Contributor

Hi,

many thanks for your reply.

Even with VPN Tunnel Sharing to "pair of hosts" didn't work. the discuss you share give some hints to solve this issue.

After change IKE v2 to IKE v1 on  Zyxel all tunnels get up and the traffic works fine. 

Once again, thank you very much.

0 Kudos
Timothy_Hall
Champion
Champion

Yeah unfortunately interoperability between vendors is still pretty spotty with IKEv2, seen issues like this many many times.  It took IKEv1 seemingly about 10 years to work properly between all the vendors, so my advice when setting up an interoperable VPN is to give IKEv2 a shot, and if there are any problems do not hesitate to go back to IKEv1.

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com