This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN tunnel between UTM and USG issue

Hello guys,

Trying to get a IPSec tunnel between our HO UTM and a USG we got for testing. Currently have it on my home network, seeing if I can get a IPSec tunnel going.

In logs, I keep getting: "MyWANIP":500: ignoring informational payload, type NO_PROPOSAL_CHOSEN

As far as I can tell, everything seems to be okay. Here's what I have configured on the UTM:

On the USG side, here is what is configured:

I think I might need a fresh set of eyes on this, I can't figure out the issue. I was initially thinking it might have been ports 4500 and 500 being blocked, but can't see any entries on the firewall log pointing to that. We also have L2TP over IPSec enabled, with users remoting in. The above message is what shows up on the IPSec VPN log for the UTM that relates to my home WAN IP.

Thank you



This thread was automatically locked due to age.
Parents
  • Hi Guys,

    Quick update, I have managed to get the tunnel up.

    As suggested by @jprusch the USG is now on a DMZ on my home network.

    The "Local WAN IP" on the USG is now 192.168.0.59, which is it's WAN IP that it got assigned from my main home router.

    The "Peer WAN IP" is the main IP, since we have a /28 subnet of external IP's at work, I set it to be the first one.

    On the UTM, in "Remote Gateways", I set the "VPN ID (optional)" to be 192.168.0.59 and that's seemed to get the tunnel up.

    Now, I got another couple of issues, which I assume and hope will be something simple.

    Connections seem to work from the USG to the UTM, but not the other way round.

    Thanks guys, really appreciated.

Reply
  • Hi Guys,

    Quick update, I have managed to get the tunnel up.

    As suggested by @jprusch the USG is now on a DMZ on my home network.

    The "Local WAN IP" on the USG is now 192.168.0.59, which is it's WAN IP that it got assigned from my main home router.

    The "Peer WAN IP" is the main IP, since we have a /28 subnet of external IP's at work, I set it to be the first one.

    On the UTM, in "Remote Gateways", I set the "VPN ID (optional)" to be 192.168.0.59 and that's seemed to get the tunnel up.

    Now, I got another couple of issues, which I assume and hope will be something simple.

    Connections seem to work from the USG to the UTM, but not the other way round.

    Thanks guys, really appreciated.

Children