QuestionQ26

Network Security

Match the IPsec faults with their possible causes.

Drag & Drop
The ACL-encrypted data flow does not contain the service to be encrypted.
ACL-encrypted data flows at both ends do not overlap.
No security policy is configured on the firewall to allow data flows from the Untrust zone to the Local zone.
The encrypted VPN data flow matches the source NAT policy, and the source address is translated.
Explanation

On Huawei firewalls, if the ACL used to define encrypted traffic does not actually include the service that needs protecting, no matching traffic ever arrives to trigger IKE negotiation in the first place. If the interzone security policy does not permit data flows from the Untrust zone to the Local zone, IKE negotiation packets destined for the firewall itself are dropped, so IKE SA negotiation fails even though the ACLs and pre-shared keys may be correct. When the ACL-encrypted data flows configured at the two IPsec peers do not mirror/overlap each other, IKE Phase 1 can still succeed but the IPsec SA (Phase 2) negotiation fails because the proxy IDs presented by each side don't match. Finally, if a source NAT policy on the firewall translates the source address of traffic that is also supposed to be encrypted, that traffic no longer matches the IPsec policy's ACL after translation, so it bypasses the tunnel and previously working IPsec VPN services are interrupted.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!