Help Center/ Virtual Private Network/ FAQs/ VPN Negotiation and Interconnection/ What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?
Updated on 2024-07-23 GMT+08:00

What Should I Do If My Firewall Cannot Receive Response Packets from the VPN Gateway in IKE Phase 1?

  1. Check whether the public IP addresses of the two ends can communicate with each other by running the ping command. By default, the VPN gateway EIPs can be pinged.
  2. Verify that the on-premises gateway (firewall) and VPN gateway can exchange packets with UDP ports 500 and 4500.
  3. Verify that the source port number is not translated when the on-premises gateway connects to the VPN gateway. In a NAT traversal scenario, ensure that the source port number is not changed after NAT traversal.
  4. Verify that IKE negotiation parameter settings are consistent at the two ends of the VPN.

    In a NAT traversal scenario, set the customer ID type to IP address and the value to the post-NAT public IP address of the on-premises gateway.