Site-to-Site VPN Unable to Ping

Kris Barlow

Honorable
Jun 21, 2013
2
0
10,510
Hello,

I recently upgrade my company's main office firewall from a Netgear FVS336G to a ZyWALL USG 300. Prior to the upgrade I had another FVS336G at a satellite office and used the two Netgear devices to service a site-to-site VPN.

Since installing the ZyWALL at the main office I can no longer ping either subnet from the respective other side. I have deleted and reconfigured the VPN settings on both sides multiple times, being very deliberate in each setting. The connection does immediately come up and log files verify a successful tunnel has been built, but the pings are not flowing.

I have created policy routes on the ZyWALL to route traffic from one side's subnet to the other and vice versa.

I have also tried a few different firewall rules in addition to two default ZyWALL rules surrounding the IPSec_VPN zone to no avail.

Any help would be greatly appreciated. My next step will be to simply connect the old FVS336G to another public IP from my ISP and go back to it as my VPN solution.

-Kris
 

Kris Barlow

Honorable
Jun 21, 2013
2
0
10,510


Thanks for the tip, as I hadn't tried an explicit firewall entry for ICMP. Sadly, though, after adding that I still go "Request timed out" on both ends.