IPsec site-to-site ErrorCode: gateway_45002

IPsec site-to-site ErrorCode: gateway_45002

IPsec site-to-site ErrorCode: gateway_45002
IPsec site-to-site ErrorCode: gateway_45002
Tuesday - last edited Wednesday
Tags: #VPN
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.2 Build 20250610 Rel.85512

Hello, when configuring IPsec VPN site-to-site settings, the following error appears: "Typical VPN policy errors"
 

The local subnet and remote subnet cannot overlap with those of existing IPsec policies. (ErrorCode: gateway_45002)

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:IPsec site-to-site ErrorCode: gateway_45002-Solution
Wednesday - last edited Wednesday

  @Istam 

 

those pictures don't tell me anything, but you are using public ip in the vpn tunnel 180.80.40.0/24 is not a private ip.

if you have all the routers configured on the same controller then i recommend you to try SD-WAN. it is much easier

 

 

Recommended Solution
  0  
  0  
#5
Options
9 Reply
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @Istam 

 

The message says that there is an overlap between your local and remote networks.
You cannot use the same remote network in the ipsec configuration as any of your local networks.

 

  0  
  0  
#2
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @MR.S 

Even though I manually write the IPsec VPN settings, it gives this error, both IPs are different from each other, but still there is this error, when I configure this second IPsec, it gives this error, the first one did not have this error. I will also attach the project topology, maybe there is a topology error

 




  0  
  0  
#3
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

 

TOPOLOGY

  0  
  0  
#4
Options
Re:IPsec site-to-site ErrorCode: gateway_45002-Solution
Wednesday - last edited Wednesday

  @Istam 

 

those pictures don't tell me anything, but you are using public ip in the vpn tunnel 180.80.40.0/24 is not a private ip.

if you have all the routers configured on the same controller then i recommend you to try SD-WAN. it is much easier

 

 

Recommended Solution
  0  
  0  
#5
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @MR.S 

Thank you for your recommendation, but now I can't update the device firmware via the Controller, I get an https error.

  0  
  0  
#6
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @Istam 

 

If you use SD-WAN or regular site to site, there is no difference in how they communicate. What you have to make sure is that the devices to be upgraded have access to the management port, if you have an OC300, it is default TCP/443. You have to port forward this port to the OC300 and UDP 29810 and TCP 29811-29817 for the other ports. How do the devices at the remote sites communicate with your controller now?

Can you take a picture of the error message you get when you try to upgrade?

 

  0  
  0  
#7
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @MR.S 

 

 

I can't show the error image now because I had already manually updated the devices after this error occurred. But as you said, port 443 in NAT was not opened to the controller because it was used for another purpose and this port is busy. Is it possible to use another port for the controller?

 

  0  
  0  
#8
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @Istam 

 

yes you can change the port in global settings and system settings

reboot controller after changing the port

 

  0  
  0  
#9
Options
Re:IPsec site-to-site ErrorCode: gateway_45002
Wednesday

  @MR.S 

 

Thank you very much, everything is working as it should, no problems.

  1  
  1  
#10
Options