Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » ZyXEL » SPI:0x0 SEQ:0x0 No rule found, Dropping packet
Search Topic:
Uniqs:
864
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Zywall SSL 10 PPPOE problem »
« AP: lost some Instant Messengers  
AuthorAll Replies
-


santtu

@elisa-laajakaista.fi

reply to Brano
Re: SPI:0x0 SEQ:0x0 No rule found, Dropping packet

Thanks Brano for your answer.

The only policy routes (in addition to USG default WAN TRUNK routes) we have added are:
(fields: Incoming, Source, Destination, Service, Next-hop, Snat)
lan1 LAN1_SUBNET RemoteLAN_SUBNET  any RemoteNetwork  none
lan1 LAN1_SUBNET Remote2LAN_SUBNET any Remote2Network none


Address definitions are:
LAN1_SUBNET	       INTERFACE SUBNET	lan1-10.22.19.0/24
RemoteLAN_SUBNET SUBNET 10.22.15.0/24
Remote2LAN_SUBNET SUBNET 10.22.10.0/24


Should I make another rule for "Zywall to remote lan"? Looks like LAN1_SUBNET is only for packets coming into Zywall LAN interface, but not from Zywall itself?

BR,

Santtu


Brano
I hate Vogons
Premium,MVM
join:2002-06-25
Burlington, ON
reply to santtu
It depends how are your routes setup on USG.
Post a screenshot.


santtu

@elisa-laajakaista.fi

Hi guys,

We have IPSec VPN tunnel between two offices, the remote office has ZW5 and our office new USG-100. Our office does not have any servers etc. and we are using resources of remote office (AD, file server, DNS). I am wondering what kind of rule is missing because we get constant errors to USG-100 logs:

error IPSec SPI:0x0 SEQ:0x0 No rule found, Dropping packet 10.22.19.1:33496 10.22.15.10:53 IPsec

The 10.22.19.1 is USG-100 LAN address, and 10.22.15.10 is DNS server of remote office. It looks like USG-100 is blocking all DNS queries to remote office when the query originates from USG-100 itself. However, DNS works when queries originate from our computers in LAN.

We have policy route definition:

lan1 LAN1_SUBNET RemoteLAN_SUBNET any RemoteNetwork none

and when I tried to create similar policy route but replacing incoming interface lan1 with "Zywall", that did not help.

Any ideas or tips?

Thanks,

Santtu
Forums » Equipment Support » Hardware By Brand » ZyXELZywall SSL 10 PPPOE problem »
« AP: lost some Instant Messengers  


Sunday, 06-Dec 05:03:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [124] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Is there any true cure for, or way to prevent, a hangover? [General Questions]
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· [Proggy] Google Voice dialer [VOIP Tech Chat]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· [Scam] Ebay Motors Scam [Spam, Scam and Phishbusters]