IPsec Problem with ER6120 and R600VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

IPsec Problem with ER6120 and R600VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
IPsec Problem with ER6120 and R600VPN
IPsec Problem with ER6120 and R600VPN
2014-01-25 11:26:35 - last edited 2021-08-21 03:46:12
Region : Austria

Model : TL-ER6120

Hardware Version : V1

Firmware Version : 1.0.6 Build 20131129 Rel.49461

ISP : UPC - A1


I have in my office the ER6120 and on the remote site the R600VPN. On both sites I have a NAT "device", which comes from the ISP. On these devices is no firewall configured. But there is a port forwarding (500) to the privat/local IP-Adresses of the VPN gateways configured.

On both VPN gateways are the official Internet IPs for the "remote gateway" of the internet connection configured. In the log I get the following messages:

office (ER6120):
2014-01-25 04:21:50 <5> : IKE began to negotiate as responder. Mode=main,peers=172.20.1.2<->89.144.202.159

remote site R600VPN):
145 Jan 25 04:22:30 VPN ERROR phase2 negotiation failed due to time up waiting for phase1. ESP 213.47.1.106[0]->192.168.99.1[0]
144 Jan 25 04:22:29 VPN INFO ISAKMP-SA deleted 192.168.99.1[4500]-213.47.1.106[4500] spi:ff796aaee244534f:678b057f1fe876cd
143 Jan 25 04:22:10 VPN INFO NAT detected: ME PEER
142 Jan 25 04:22:09 VPN INFO Selected NAT-T version: RFC 3947
141 Jan 25 04:22:09 VPN INFO initiate new phase 1 negotiation: 192.168.99.1[500]<=>213.47.1.106[500

What´s wrong? Where is the failure?

Regards
Thomas
  0      
  0      
#1
Options
1 Reply
Re:IPsec Problem with ER6120 and R600VPN
2014-01-26 08:08:42 - last edited 2021-08-21 03:46:12
You may try use Domain Name instead, FQDN as the IP identified .
  0  
  0  
#2
Options