yes but the end that is seeing things as spoofed, is the NEW end. Also, I did rebuild the VPN from scratch.
any other ideas?
Main Topics
Browse All TopicsI am replacing one end of a site to site IPSEC VPN. Both ends used to be pfsense but now on one end I am using a ZyXel ZyWall 5. I believe I have the two endpoints negotiating both phases properly, and the VPN shows up as active and working in both the pfsense and ZyWall interfaces. I just cannot ping either network from the other side. the main office network (with the pfsense) subnet is 10.10.10.0 /24 and the satellite office network (ZyWall) is 192.168.10.0 /24.
as far as firewall rules go, on the pfsense I have an IPSEC rule that traffic is wide open (works on all other VPN endpoints) and on the ZyWall i have the default setup, which is OPEN.
Here is a line from the ZyWall logs which I think describes a computer at the main office trying to ping the ZyWall:
# Time Message Source Destination Note
3 [xx] ip spoofing - WAN ICMP (V to V/ZW, Echo) 10.10.10.25 192.168.10.1 ATTACK
thanks!
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: jfer0x01Posted on 2009-10-10 at 11:56:07ID: 25543351
if you replaced one end, the MAC address chagned for th other device,
thats probably why it thinks the source ip is spoofed
rebuild the VPN from scratch.
Jfer