Support on SonicWall Products, Services and Solutions
Browse Knowledgebase by Category
VPN Tunnel to Draytek - Multiple subnets but only one Security Association created
03/26/2020 8 11069
A VPN Tunnel to Draytek is going up with only one Security Association (SA) although there are many Local/Destination Networks so more SAs should be created.
It looks like Draytek does not fully support multiple phase 2 security associations for a single VPN Policy with the default settings.
To fix this, the option "Create Phase 2 SA for each subnet" has to be enabled on the Draytek (Vigor) router:
However, this may not work if you have the Perfect Forward Secrecy option disabled on the SonicWall. Please enable it from the configuration of the VPN Tunnel to the Draytek:
For further details: How to Create Phase2 SA for Multiple Subnets - Draytek Website