Knowledge Base

Why is the non-Nebula site to site VPN tunnel not stable?

Question

Why is the non-Nebula site to site VPN tunnel not stable?

 

Answer

 

Via logs, we can find that the tunnel is establish for a few seconds then disconnects, immediately.

 

NSG uses connectivity check to the peer site LAN interface, to check if the tunnel is still alive or not.

In private subnet, if the remote policy is 192.168.35.0/24, then the NSG will ping to 192.168.35.1, if it is not your peer site LAN interface then the tunnel will disconnect, due to not receiving any response.

For instance, if your peer site LAN interface IP is 192.168.35.254, please fill out 192.168.35.254/24 instead of 192.168.35.0/24

 



YES NO

Please leave your comment:

SUBMIT

Question Profile

LANGUAGE:
ARTICLE ID:016965
TYPE:General Info
FIRMWARE:1.20 or latest
VIEWS:712
VOTES:1
TECHNOLOGY:
MODEL:NSG100,NSG200,NSG50 (view more model name)

Still have trouble with your device? Contact Zyxel technology support team directly!

Contact Zyxel Support