Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
YvesSYN
New Contributor

IPSEC between 110c and Zyxel NAT traversal

hi I need help for configuring vpn ipsec site to site in this case: site 1 : Zyxel usg 20 Lan 10.4.0.250/16 Wan 82.x.x.243 site 2 : D-Link DSL-2542B Lan 192.168.0.252/24 Wan 193.x.x.161 Fortigate 110c Lan 192.168.1.242/24 Wan 192.168.0.1/24 Hp 3xvl lan1 192.168.1.254/24 lan2 10.0.0.235/16 *** on f110c *** phase1 juv_ter remote gw statis ip address = 82.x.x.243 local interface wan1(WAN) mode main auth. method preshared key " mykey" with enable ipsec interface mode ike version1 local Gateway IP Main Interface IP P1 porposal DES MD5 DH2 keylife 86400 local id empty xauth disable nat traversal enable etc. phase 2 routing and policy (not the problem for the moment, phase 1 didn' t work) *** on zyxel *** peer Gateway = dynamic adress authentication pre-shared key = " mykey" sa life time 86400 negociation mode main proposal des md5 dh2 nat traversal enable the vpn didn' t bring up on fortigate i have in logs negociate / progess IPsec hase 1 IPSec remote IP 82.x.x.243 IPSec local IP 192.168.0.1 status success delete_phase1_sa / delete IPsec phase 1 SA on zyxel i have recv main mode request from 193.x.x.161 cookie recv sa VID VID VID cookie Send SA recv KE NOTICE Send NOTIFY AUTHENTICATION FAILED can you help me please ? thanks
4 REPLIES 4
abc987
New Contributor II

I don' t know any detail of this Zyxel. But I think if you use ' peer gateway = dynamic adress' maybe it expects ID settings for P1 authentication (and aggressive mode) (Is it a dynamic IP at that D-Link? Can you use this D-Link as modem-only? Then you could set PPPoE at 110C without NAT-T)

FCNSP/WCSP

FCNSP/WCSP
YvesSYN
New Contributor

Hi I try to set peer ID on the fortigate, but i did' nt find where: In edit phase 1, if i set Aggressive, i have only 2 choices : Accept any peer ID or Accept this peer ID The zyxel request both local and remote peer ID The D-Link cannot be used as modem-only it' s a static IP at that D-Link so i try peer Gateway = 193.x.x.161 on the zyxel that doesn' t work I' ve got authentication failure on the zyxel thanks
abc987
New Contributor II

Accept this peer ID -> fill with local ID from your Zyxel The local ID on Forti you can find under Phase1->Advanced->P1 Proposal->Local ID Fill this with the ' remote ID' you have configured at your Zyxel

FCNSP/WCSP

FCNSP/WCSP
YvesSYN
New Contributor

hi I found how to set the dlink as a modem and that' s work thanks for the help
Labels
Top Kudoed Authors