Help Center> Virtual Private Network> FAQs> VPN Negotiation and Interconnection> What Should I Do If My Firewall Cannot Receive Response Packets from the Huawei Cloud VPN Gateway in IKE Phase 1?
Updated on 2023-06-16 GMT+08:00

What Should I Do If My Firewall Cannot Receive Response Packets from the Huawei Cloud VPN Gateway in IKE Phase 1?

  1. Check whether the public IP addresses of the two ends can communicate with each other by running the ping command. By default, the VPN gateway EIPs on Huawei Cloud can be pinged.
  2. Verify that the on-premises gateway (firewall) and Huawei Cloud VPN gateway can exchange packets with UDP ports 500 and 4500.
  3. Verify that the source port number is not translated when the on-premises gateway accesses the VPN gateway on Huawei Cloud. In a NAT traversal scenario, ensure that the source port number is not changed after NAT traversal.
  4. Verify that IKE negotiation parameter settings are consistent at the two ends of the VPN.

    In a NAT traversal scenario, set the customer ID type to IP address and the value to the post-NAT public IP address of the on-premises gateway.

VPN Negotiation and Interconnection FAQs

more