Help Center/ Virtual Private Network/ FAQs/ FAQs - S2C Classic VPN/ VPN Negotiation and Interconnection/ What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?
Updated on 2024-07-23 GMT+08:00

What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?

  1. Check whether the public IP addresses of the two ends can communicate with each other by running the ping command. By default, the cloud-side gateway IP address can be pinged.
  2. Verify that the on-premises gateway (firewall) and cloud-side gateway can exchange packets through UDP ports 500 and 4500.
  3. Verify that the source port number is not translated when the on-premises gateway connects to the cloud-side gateway. In a NAT traversal scenario, ensure that the source port number is not changed after NAT traversal.
  4. The IKE negotiation settings at both ends must be the same. In the NAT traversal scenario, set the ID type in the on-premises data center to IP and the local ID on the cloud side to the post-NAT public IP address.