Hello, everyone,

Currently I have the problem to build an IPSec tunnel between a PA200 (A) and a PA220 (B).
My one side A has a Telekom hybrid Internet connection (its a german product with LTE and cable connection) to a Speedport router. Thus only one dynamic official IP.
The other side B is a normal company connection with a fixed IP address. I have configured my tunnel so that only side A is allowed to start the tunnel. (B side enable passive mode)

If I now start the tunnel on page A, I also see in the monitoring at page B the requests ike on port 500 for port 500. Unfortunately then nothing happens further and page A has then a Faild Due to timeout.
You can also see that page A transmits data but does not receive any data.
What could that be? What is the best way to narrow down the problem?

Have you configured Proxy-IDs, as if the PA wants to establish an IPSec tunnel with Non-PA device, we need to configure it because of Route based approach.

I have sites with multiple VPN's and I think I understand what you are trying to accomplish. You want all traffic to go down TunnelA as primary with TunnelB as secondary? If yes, setup the tunnels the same with settings on both. Both tunnels will be up at the same time, this is OK. Then control traffic with routing, either static routes with monitors and weights or OSPF with Metrics.


Hope that helps.

