• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1226
  • Last Modified:

Zywall to Watchguard

I have reached the end of my rope on this one. I have two firewalls, a Zywall 70 and a WatchGuard Firebox X5 Edge V7.5. I am trying to setup a VPN between the two and I can't get it to pass traffic. The Zywall says the connection is active, but the Firebox does not. Here is the configuration for the Zywall

Local Network
Range Address

Remote Network
Range Address

Gateway Policy Information
My Zywall
Primary Remote Gateway

Manual Proposal
SPI - 1
Encapsulation Mode  - Tunnel
Active Protocol - ESP
Encryption Algorithm 3DES
Authentication Algorithm SHA1

I have not include the encryption keys for security reasons, but I have double checked to make sure they are the same on both firewalls.

Here is the configuration for the Firebox

Phase 1 Settings
Mode- Main Mode
Remote IP Address
             Local ID -   Type: IP Addr
             Remote ID -   Type: IP Addr
Authentication Algorithem- SHA1-HMAC
Encryption Algorithm 3DES-CBC
Negotiation Expires in 0 KB
Negotiation expires in 24 hours
Diffie-Helman Group - 1
Yes to Send IKE keep alive messages

Phase 2 settings
Authentication Algorithm- SHA-HMAC
Encryption Algorithm- 3DES-CBC
Local Network
Remote Network

Any guidance on how I can get this working would be greatly appreciated.
1 Solution
The settings look good; can you post few sanitized logs which would help understand which settings is not matching at the ends.

Also, have you got any other VPN tunnel working on these boxes; just want to make sure that ISP is not blocking the VPN traffic.

Thank you.
The Zywall config should also havea  section like this, which you should feed in teh complimentary data.

Remote IP Address
             Local ID -   Type: IP Addr
             Remote ID -   Type: IP Addr

What does the log on each box show as the tunnel is brought up?

Oh - and you might try putting the Local and Remote network addresses in as "networks" not "ranges" in the zywall to match what you have done on the Watchguard - though I don't think it matters. Can't hurt to be consistent.
one2onelancAuthor Commented:
Thanks for the tips but we ending up scraping this project, we are going to get two zywalls instead.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Managing Security & Risk at the Speed of Business

Gartner Research VP, Neil McDonald & AlgoSec CTO, Prof. Avishai Wool, discuss the business-driven approach to automated security policy management, its benefits and how to align security policy management with business processes to address today's security challenges.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now