<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>SPI:0x0 SEQ:0x0 No rule found, Dropping packet in ZyXEL</title>
<link>http://www.dslreports.com/forum/r22564191</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 09:52:59 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 09:52:59 EDT</lastBuildDate>

<item>
<title>Re: SPI:0x0 SEQ:0x0 No rule found, Dropping packet</title>
<link>http://www.dslreports.com/forum/remark,22595108</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks Brano for your answer.<br><br>The only policy routes (in addition to USG default WAN TRUNK routes) we have added are:<br><i>(fields: Incoming, Source, Destination, Service, Next-hop, Snat)</i><br><pre><b>lan1 LAN1_SUBNET RemoteLAN_SUBNET  any RemoteNetwork  none<br>lan1 LAN1_SUBNET Remote2LAN_SUBNET any Remote2Network none</b></pre><br><br>Address definitions are:<br><pre><b>LAN1_SUBNET&#9;       INTERFACE SUBNET&#9;lan1-10.22.19.0/24<br>RemoteLAN_SUBNET&#9;SUBNET&#9;              10.22.15.0/24<br>Remote2LAN_SUBNET&#9;SUBNET&#9;              10.22.10.0/24<br></b></pre><br><br>Should I make another rule for "Zywall to remote lan"? Looks like LAN1_SUBNET is only for packets coming into Zywall LAN interface, but not from Zywall itself? <br><br>BR,<br><br>Santtu<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22595108</guid>
<pubDate>Tue, 23 Jun 2009 05:39:46 EDT</pubDate>
</item>

<item>
<title>Re: SPI:0x0 SEQ:0x0 No rule found, Dropping packet</title>
<link>http://www.dslreports.com/forum/remark,22565140</link>
<description><![CDATA[<A HREF="/useremail/u/649954"><b>Brano</b></A> : It depends how are your routes setup on USG.<br>Post a screenshot.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22565140</guid>
<pubDate>Wed, 17 Jun 2009 10:18:44 EDT</pubDate>
</item>

<item>
<title>SPI:0x0 SEQ:0x0 No rule found, Dropping packet</title>
<link>http://www.dslreports.com/forum/remark,22564191</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi guys,<br><br>We have IPSec VPN tunnel between two offices, the remote office has ZW5 and our office new USG-100. Our office does not have any servers etc. and we are using resources of remote office (AD, file server, DNS). I am wondering what kind of rule is missing because we get constant errors to USG-100 logs:<br><br>error&#9;IPSec&#9;SPI:0x0 SEQ:0x0 No rule found, Dropping packet&#9;10.22.19.1:33496&#9;10.22.15.10:53&#9;IPsec<br><br>The 10.22.19.1 is USG-100 LAN address, and 10.22.15.10 is DNS server of remote office. It looks like USG-100 is blocking all DNS queries to remote office when the query originates from USG-100 itself. However, DNS works when queries originate from our computers in LAN. <br><br>We have policy route definition:<br><br>lan1&#9;LAN1_SUBNET&#9;RemoteLAN_SUBNET&#9;any&#9;RemoteNetwork&#9;none<br><br>and when I tried to create similar policy route but replacing incoming interface lan1 with "Zywall", that did not help.<br><br>Any ideas or tips? <br><br>Thanks,<br><br>Santtu ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22564191</guid>
<pubDate>Wed, 17 Jun 2009 03:50:26 EDT</pubDate>
</item>

</channel>
</rss>
