Match the IPsec faults with their possible causes.
On Huawei firewalls, if the ACL used to define encrypted traffic does not actually include the service that needs protecting, no matching traffic ever arrives to trigger IKE negotiation in the first place. If the interzone security policy does not permit data flows from the Untrust zone to the Local zone, IKE negotiation packets destined for the firewall itself are dropped, so IKE SA negotiation fails even though the ACLs and pre-shared keys may be correct. When the ACL-encrypted data flows configured at the two IPsec peers do not mirror/overlap each other, IKE Phase 1 can still succeed but the IPsec SA (Phase 2) negotiation fails because the proxy IDs presented by each side don't match. Finally, if a source NAT policy on the firewall translates the source address of traffic that is also supposed to be encrypted, that traffic no longer matches the IPsec policy's ACL after translation, so it bypasses the tunnel and previously working IPsec VPN services are interrupted.
Community Discussion