Customer want to configure IPsec Site to Site VPN between Huawei USG6300 and third-part Firewall, after configuring all required parameters successfully on both ends, But it not working and getting error after diagnosis.
Product: Huawei USG6600 V500R001C60SPC200
Third-part device: Checkpoint
1 Compare the ike and ipsec configuration found all of the parameter is same.
USG6600 configuration as follow:
CheckPoint Firewall Configuration as follow:
Remote Address Pool:10.91.0.0/16
Local Address Pool:172.18.0.0/16
SA Timeout:By time:3600 Seconds
By Traffic:20971520 KB
2 Check the security policy and NAT policy configuration
3 Check the route table
ike version and dh group can’t negotiate successfully with third-part firewall,
Change the IKE version from V2 to V1 and DH group from 14 to 2 between both sides firewall.
There may have compatibility issues when establish IPsec VPN between third-part firewall.it is recommend use the single algorithm example DES、MD5 without SHA2, and IKE use V1.