RV50X and RV55 IPSec config

I am struggling with making sense of SW’s vpn terminology and implementation. How would I configure this in a RV50X or RV55? I can get my tunnel up, but no traffic over it.

Particular settings I am confused about: IPSEC Local Termination, Local Address Type, Local Address/Subnet, Remote Address/Subnet List, Remote Address/Subnet Exemption List.

Please see attached diagram.

Hi henry.fordyce,

Your setting is LAN-to-LAN, so IPSEC Local Termination should be set to LAN. Leave Local Address Type as default. Local Address/Subnet is the IP Address or subnet behind your RV50X. Remote Address/Subnet List is the IP Address or subnet behind your VPN server. Exemption List is at which your traffic is not authenticated or encrypted or both; in this case, leave it blank.

I need to take a look at your configuration. Please share your configuration by going to ACEmanager → Template → Enter template name and download. Before sending your configuration file, you should open it and delete your sensitive info such as WAN IP, VPN server…

Thanks,

I just want to say thanks! Your information helped!

Hi! I’m working on a similar deployment. My tunnel is established with a Palo Alto Firewall, but I can’t make any traffic transit over it. I already added a desired subnet in the “Subnet List”. The local subnet I left it at the default “192.168.13.0/24” and the Sierra Wireless RV50X has the default 192.168.13.31 on its LAN interface. When I take a packet capture on the other end, I dont see anything. Would you confirm if from what I said there is something wrong and also any steps you took to solve the issue.

Thanks!

I have a similar IPSEC setup btwn 2 RV50. TCP and ICMP works but UDP (ie SNMP and syslog) is not. I’m running 4.16 and 4.9.3. Wireshark shows no reply when I do a SNMP walk. Any ideas?

Thanks in advance

I am trying to connect a red lion sn-6901 cellular router to a sierra wireless rv50x with a vpn and have tried multiple setting configuration but cannot establish a connection. Any help or ideas are greatly appreciated.