Help Center/ Virtual Private Network/ FAQs/ FAQs - S2C Enterprise Edition VPN/ VPN Negotiation and Interconnection/ What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?
Updated on 2025-01-23 GMT+08:00
What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?
- Check whether the public IP addresses of the two ends can communicate with each other by running the ping command. By default, the VPN gateway EIPs can be pinged.
- Verify that the on-premises gateway (firewall) and VPN gateway can exchange packets with UDP ports 500 and 4500.
- Verify that the source port number is not translated when the on-premises gateway connects to the VPN gateway. In a NAT traversal scenario, ensure that the source port number is not changed after NAT traversal.
- Verify that IKE negotiation parameter settings are consistent at the two ends of the VPN.
In a NAT traversal scenario, set the customer ID type to IP address and the value to the post-NAT public IP address of the on-premises gateway.
Parent topic: VPN Negotiation and Interconnection
What is your overall rating for this page?
0
1
2
3
4
5
6
7
8
9
10
Very dissatisfiedVery satisfied
Thank you very much for your feedback. We will continue working to improve the documentation.
The system is busy. Please try again later.