I have a SSG-520M with Software Version: 6.3.0r5.0 as my edge Firewall/VPN gateway. I will be using LAN-2-LAN VPN tunnels as well as Dialup VPN connections. I am using Netscreen-remote 10.8.10 software to connect to my VPN gateway. May problem is that I can connect successfully to the VPN gate via the untrusted interface (eth0/2), but from the dialup connected laptop I am only able to communicate to the DMZ interface on the VPN GW (eth0/1) and that is only when I change from the DMZ zone to a trusted zone on eth0/1. However, I am still not able communicate to any other interface in the 172.16.100.0/24 subnet (The cisco switch or the DMZ firewall). I am able to talk to the cisco switch and the DMZ firewall directly from the VPN Gateway/Firewall. I put VPN monitoring on the Eth0/2 interface on the VPN GW and saw that the SA is active but the link is showing down. I need some help please.
VPN Name SA ID Policy ID Peer Gateway IP Type SA Status Link
ApptisDialupv2 00000009 2/-1 126.96.36.199 AutoIKE Active Down