Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec VPN Blocked (UDP port closed !)

Hi,

i have a ZTE router F660 and an XGS107, we have a fixed IP from ISP and when we try to connect to with IPSec client it says that UDP IKE port is blocked.

in ZTE configuration we disabled DHCP and added XGS107 ip in DMZ, internet access is working from LAN.

i treid a scan with nmap and is seems that ports are open

Starting Nmap 7.93 ( https://nmap.org ) at 2022-10-27 10:50 Maroc (heure d’été)

Nmap scan report for 196.xx.yyy.zzz

Host is up.



PORT     STATE         SERVICE

500/udp  open|filtered isakmp

4500/udp open|filtered nat-t-ike



Nmap done: 1 IP address (1 host up) scanned in 20.52 seconds

checked the scvpnlog and here's what it says

022-10-27 10:49:28AM [33584] dbg RIM_VPN VPN state changed to connecting
2022-10-27 10:49:28AM [33584] dbg Starting tunnel (connecting)
2022-10-27 10:49:28AM [33584] dbg Connection to strongSwan has been established
2022-10-27 10:49:31AM [33584] dbg Sending notification: The IKE UDP port seems to be blocked
2022-10-27 10:49:33AM [33584] dbg Initiating connection RIM_VPN
2022-10-27 10:49:33AM [23892] dbg IKE being initiated to IP address 196.xx.yyy.zzz
2022-10-27 10:49:55AM [33584] err Tunnel initiate to 196.xx.yyy.zzz failed: 1036 - No response from gateway: 196.xx.yyy.zzz
2022-10-27 10:49:55AM [33584] dbg Unloading configuration for connection RIM_VPN
2022-10-27 10:49:56AM [33584] dbg Connection to strongSwan has been closed
2022-10-27 10:49:56AM [33584] dbg RIM_VPN VPN state changed to reconnecting
2022-10-27 10:49:56AM [33584] dbg Sending notification: No response from gateway: 196.xx.yyy.zzz
2022-10-27 10:50:26AM [34576] dbg RIM_VPN VPN state changed to reconnecting
2022-10-27 10:50:26AM [34576] dbg Starting tunnel (reconnecting)
2022-10-27 10:50:26AM [34576] dbg Connection to strongSwan has been established
2022-10-27 10:50:28AM [34576] dbg Sending notification: The IKE UDP port seems to be blocked
2022-10-27 10:50:31AM [34576] dbg Initiating connection RIM_VPN
2022-10-27 10:50:31AM [32128] dbg IKE being initiated to IP address 196.xx.yyy.zzz
2022-10-27 10:50:53AM [34576] err Tunnel initiate to 196.xx.yyy.zzz failed: 1036 - No response from gateway: 196.xx.yyy.zzz
2022-10-27 10:50:53AM [34576] dbg Unloading configuration for connection RIM_VPN
2022-10-27 10:50:54AM [34576] dbg Connection to strongSwan has been closed
2022-10-27 10:50:54AM [34576] dbg RIM_VPN VPN state changed to reconnecting
2022-10-27 10:50:54AM [34576] dbg Sending notification: No response from gateway: 196.xx.yyy.zzz
2022-10-27 10:51:09AM [2860] dbg RIM_VPN VPN state changed to disconnecting
2022-10-27 10:51:09AM [2860] dbg RIM_VPN VPN state changed to disconnected

can someone help with this issue.

best regards.



This thread was automatically locked due to age.
Parents
  • I think, you try the nmap-scan from external internet-ip...?

    At the ZTE router do you forward ports UDP500 & UDP4500 to the Firewall?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • I think, you try the nmap-scan from external internet-ip...?

    At the ZTE router do you forward ports UDP500 & UDP4500 to the Firewall?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data