
32/76
© Copyright 1995-2013, ZyXEL Communications Corp. All rights reserved.
3. Change to pre-share key. I can see the logs.
60. [BUG FIX] eITS#120301945 , SPR: 120531292
Symptom: IPSec VPN adjust MSS does not work.
Condition:
Topology:
Client --- (LAN)USG1000(Ethernet) === IPSec VPN == (PPPoE)USG300(LAN) --- Server
1. Set up a IPSec VPN tunnel between USG1000 and USG300.
2. In USG300 VPN gateway setting, try set FQDN to peer gateway address.
3. IN USG300 IPsec rule setting, try set MSS adjustment to custom size to 1000.
4. Client use TCP connect to server through IPSec VPN tunnel.
5. Check the MSS size in the SYN/ACK packet at USG1000’s LAN side, the value is not
1000.
61. [BUG FIX] eITS#120501305 , SPR: 120514003
Symptom: USG 300 reboots with coredump
Condition:
After config VPN, device will restart in 3-4 days and with a coredump.
CSO operation.
Now we are asking for their config file and topology, when we get these will try to
reproduce check could we done that in short time.
62. [BUG FIX] eITS#120500936 , SPR: 120601030
Symptom: NAT-T will auto enable, after upgrade from 2.20 to 3.00
Condition:
1. config isakmp policy without NAT-T in 2.20
2. After upgrade firmwar to 3.00 this policy will auto enable NAT-T
63. [BUG FIX] eITS#120502982 , SPR: 120531281
Symptom: :[E] USG-100 Site to Site VPN and deactivate Tunnel Issue
Condition:
Customer found even they disable the L2TP phase2 rule, when remote device want to
negotiation S2S VPN, it still try to use L2TP rule for default nego rule.
CSO operation.
We can reproduce this issue, these are our steps,
1.setup a S2S between A and B USG.
2.Enable nail-up on device A.
3.Inactive device B’s L2TP rule.
4.Let S2S build up, then inactive S2S phase2 rule on device B directly.
5.In logs we can see device A try to nego device B’s L2TP phase2.
6.Active device B’s S2S phase2 then S2S become normal.
64. [BUG FIX] eITS#120400091, SPR: 120605200
Kommentare zu diesen Handbüchern