A Broadcasting & Television company uses two USG5330 to make VRRP, VPN Client version is V100R001C02SPC001. Network topology is as follows.
Figure 1 FW networking topology
Now the problem is that: customers use VPN client software to dial the external VPN in our network laboratory through, but it is impassable, prompting the information "the third step: complete IKE negotiation", then prompt connection error, "error reason: tunnel keep-alive timeout or negotiation timeout." But the same account and VPN client test in dealer network, dialing pass.