What Should I Do If My Firewall Cannot Receive Response Packets from the Huawei Cloud VPN Gateway in IKE Phase 1?
- Check whether the public IP addresses of the two ends can communicate with each other by running the ping command. By default, the VPN gateway EIPs on Huawei Cloud can be pinged.
- Verify that the on-premises gateway (firewall) and Huawei Cloud VPN gateway can exchange packets with UDP ports 500 and 4500.
- Verify that the source port number is not translated when the on-premises gateway accesses the VPN gateway on Huawei Cloud. In a NAT traversal scenario, ensure that the source port number is not changed after NAT traversal.
- Verify that IKE negotiation parameter settings are consistent at the two ends of the VPN.
In a NAT traversal scenario, set the customer ID type to IP address and the value to the post-NAT public IP address of the on-premises gateway.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.