Hello,
we have a little problem. Communication schema is :
Zyxel USG 100 ↔ NAT (forwarde UDP500,4500) ↔ INTERNET ↔ NAT (forwarde UDP500,4500) ↔ Mikrotik 2011UiAS-RM
If ZyXEL USG 100 initiate IPSEC connection to Mikrotik, then Phase1 and Phase 2 is ok and tunnel is UP and working.
If Mikrotik initiate IPSEC connection to Zyxel USG100, then Phase 1 is ok and Phase 2 not initiate.
I spoke with Zyxel support, but they told me, the Mikrotik does not have ICSA certified - not in their power to solve this problem.
I found this problem :
https://forum.pfsense.org/index.php?topic=87333.0
with this link :
https://redmine.pfsense.org/issues/4178
So, I think this is same problem, because in Zyxel USG 100 logs is in the Phase2 this debug output (leftsubnet to 0.0.0.0 ):
src=“0.0.0.0:0” dst=“0.0.0.0:0” msg=" Remote IKE peer XXX.XXX.XXX.XXX:4500 ID 10.0.0.8 (ipv4)" note=“IKE_LOG” user=“unknown” devID=“b0b2dc33858f” cat=“IKE”
At this time we using Zyxel USG on many places, but someone other Companies have different router.
Until now we don’t have problem with ZyxelUSG IPSEC communication with other routers.
Now we have this problem with Mikrotik, so we can not deploy Mikrotik massively as replacement instead Zyxel.
So, have someone same problem?
Or does anyone know if Mikrotik have plan to fully implemented IPSEC with ICSA standard / certified?
Thank you
Max Devaine