IPSec Tunnel - Phase 1 fails
- May 4, 2020
- 1 reply
- 14494 views
Odd problem that support could not help me with. Trying to bring up an IPSEC tunnel. I can create tunnels to Azure and to a spare WAN connection in out office. When I've tried to apply this config to 2 60E's in remote offices, they both failed. The only differences between these offices and our testWAN/Azure is that Azure/TestWAN receive dynamic IPs while our offices get static IPs from their ISPs and thus, have an extra route to their gateway.
When I run 'diagnose sniffer packet any "host x.x.x.x and port (500 or 4500)" 4 0 l' on our main firewall, I see the traffic go out but never come back. On the remote firewall I see the traffic come in and go back out. Support waived their hand, said the config was good and it was an ISP issue... but I have a hard time believing that two separate ISPs are causing the exact same problem. And our primary ISP allows this to Azure and our testWAN.
Summary:
-config good
-Main -> Azure Works
-Main -> testWAN (same ISP as Main, DHCP IP) works
-Main -> Branch1 (static IP from ISP1) fails
-Main -> Branch2 (static IP from ISP2) fails
