Question
IPSEC between 110c and Zyxel NAT traversal
hi I need help for configuring vpn ipsec site to site in this case: site 1 : Zyxel usg 20 Lan 10.4.0.250/16 Wan 82.x.x.243 site 2 : D-Link DSL-2542B Lan 192.168.0.252/24 Wan 193.x.x.161 Fortigate 110c Lan 192.168.1.242/24 Wan 192.168.0.1/24 Hp 3xvl lan1 192.168.1.254/24 lan2 10.0.0.235/16 *** on f110c *** phase1 juv_ter remote gw statis ip address = 82.x.x.243 local interface wan1(WAN) mode main auth. method preshared key " mykey" with enable ipsec interface mode ike version1 local Gateway IP Main Interface IP P1 porposal DES MD5 DH2 keylife 86400 local id empty xauth disable nat traversal enable etc. phase 2 routing and policy (not the problem for the moment, phase 1 didn' t work) *** on zyxel *** peer Gateway = dynamic adress authentication pre-shared key = " mykey" sa life time 86400 negociation mode main proposal des md5 dh2 nat traversal enable the vpn didn' t bring up on fortigate i have in logs negociate / progess IPsec hase 1 IPSec remote IP 82.x.x.243 IPSec local IP 192.168.0.1 status success delete_phase1_sa / delete IPsec phase 1 SA on zyxel i have recv main mode request from 193.x.x.161 cookie recv sa VID VID VID cookie Send SA recv KE NOTICE Send NOTIFY AUTHENTICATION FAILED can you help me please ? thanks
