Help Center> Virtual Private Network> FAQs> Classic VPN> VPN Negotiation and Interconnection> What Should I Do If My Firewall Cannot Receive Response Packets from the Huawei Cloud VPN Gateway in the IKE Phase?
Updated on 2023-06-16 GMT+08:00

What Should I Do If My Firewall Cannot Receive Response Packets from the Huawei Cloud VPN Gateway in the IKE Phase?

  1. Check whether the public IP addresses of the two ends can communicate with each other. You can run the ping command. By default, the VPN gateway IP address on Huawei Cloud can be pinged.
  2. The on-premises gateway and Huawei Cloud VPN gateway can exchange packets on UDP port 500 and 4500.
  3. Ensure that the source port number is not translated when the on-premises public IP address accesses the gateway IP address on Huawei Cloud. If NAT traversal exists, ensure that the port number will not be changed after NAT traversal.
  4. The IKE negotiation parameter settings at both ends must be the same. In the NAT traversal scenario, set the ID type in the on-premises data center to IP and the local ID on Huawei Cloud to the public IP address after NAT.

VPN Negotiation and Interconnection FAQs

more