Mikrotik IPSEC + ZyXEL USG

Hello,
we have a little problem. Communication schema is :

Zyxel USG 100 ↔ NAT (forwarde UDP500,4500) ↔ INTERNET ↔ NAT (forwarde UDP500,4500) ↔ Mikrotik 2011UiAS-RM


If ZyXEL USG 100 initiate IPSEC connection to Mikrotik, then Phase1 and Phase 2 is ok and tunnel is UP and working.
If Mikrotik initiate IPSEC connection to Zyxel USG100, then Phase 1 is ok and Phase 2 not initiate.

I spoke with Zyxel support, but they told me, the Mikrotik does not have ICSA certified - not in their power to solve this problem.

I found this problem :
https://forum.pfsense.org/index.php?topic=87333.0
with this link :
https://redmine.pfsense.org/issues/4178

So, I think this is same problem, because in Zyxel USG 100 logs is in the Phase2 this debug output (leftsubnet to 0.0.0.0 ):
src=“0.0.0.0:0” dst=“0.0.0.0:0” msg=" Remote IKE peer XXX.XXX.XXX.XXX:4500 ID 10.0.0.8 (ipv4)" note=“IKE_LOG” user=“unknown” devID=“b0b2dc33858f” cat=“IKE”

At this time we using Zyxel USG on many places, but someone other Companies have different router.
Until now we don’t have problem with ZyxelUSG IPSEC communication with other routers.
Now we have this problem with Mikrotik, so we can not deploy Mikrotik massively as replacement instead Zyxel.

So, have someone same problem?
Or does anyone know if Mikrotik have plan to fully implemented IPSEC with ICSA standard / certified?

Thank you
Max Devaine

It has nothing to do with ICSA. Please enable ipsec debug logs in system logging menu, try to initiate the tunnel and then generate supout file. Send that supout file to Mikrotik support.

Hello,
so, problem solved, thank you Mikrotik support.

The problem was on our side. First problem was in the Policy settings (we understand badly the policy template functions).
Second problem was on our side too, because Phase2 go up automatically only if there is communication, for example :
If Phase1 is up and I will put ping to second side, then Phase2 go up automatically (Phase2 is down until begin first communication in tunnel).

Max Devaine

Hi! It is possible to explain exactly how you have solved this Problem? Please help me, because i have the same Problem with Mikrotik as Client and a Zyxel USG60 Firewall as Server
VPN is L2TP/IPsec with pre shared key
thx