ZyXEL ZYWALL USG 100 User Guide - Page 72

ZyWALL IPSec VPN Client Configuration Provisioning Video Example, 4.4.4 What Can Go Wrong

Page 72 highlights

Chapter 4 Create Secure Connections Across the Internet 4.4.3 ZyWALL IPSec VPN Client Configuration Provisioning Video Example Use Adobe Reader 9 or later or a recent version of Foxit Reader to play this video. After clicking play, you may need to confirm that you want to play the content and click play again. 4.4.4 What Can Go Wrong • VPN rule settings violate the the ZyWALL IPSec VPN Client restrictions: Check that the rule does not contain AH active protocol, NULL encryption, SHA512 authentication, or a subnet/range remote policy. The ZyWALL IPSec VPN Client can also indicate rule violations. Check its warning screen. Although the rule settings may be valid, whether the tunnel actually works depends on the network environment. For example, a remote policy IP address for a server may be valid, but the server may be down or have an actual different IP address. • There is a login problem: Reenter the user name (Login) and password in the ZyWALL IPSec VPN Client exactly as configured on the ZyWALL or the external authentication server. Check that the client authentication method selected on the ZyWALL is where the user name and password are configured . For example, if the user name and password are configured on the ZyWALL, then the configured authentication method should be Local. 72 ZyWALL USG100-PLUS User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 4 Create Secure Connections Across the Internet
ZyWALL USG100-PLUS User’s Guide
72
4.4.3
ZyWALL IPSec VPN Client Configuration Provisioning Video Example
Use Adobe Reader 9 or later or a recent version of Foxit Reader to play this video. After clicking
play, you may need to confirm that you want to play the content and click play again.
4.4.4
What Can Go Wrong
VPN rule settings violate the the ZyWALL IPSec VPN Client restrictions:
Check that the rule does not contain
AH
active protocol,
NULL
encryption,
SHA512
authentication, or a subnet/range remote policy.
The ZyWALL IPSec VPN Client can also indicate rule violations. Check its warning screen.
Although the rule settings may be valid, whether the tunnel actually works depends on the
network environment. For example, a remote policy IP address for a server may be valid, but
the server may be down or have an actual different IP address.
There is a login problem:
Reenter the user name (
Login
) and password in the ZyWALL IPSec VPN Client exactly as
configured on the ZyWALL or the external authentication server.
Check that the client authentication method selected on the ZyWALL is where the user name
and password are configured . For example, if the user name and password are configured on
the ZyWALL, then the configured authentication method should be
Local
.