USG20-VPN WITH NAT AND VIRTUAL IP
Hello!
I have a USG20-VPN factory restored, and ready to be configured!
I need to install it in a already built network (192.168.1.0/24) because I have some devices that I want to reach with SSL VPN.
I try to explain what I think to do:
I attach an image to explain the situation:
I have a USG20-VPN factory restored, and ready to be configured!
I need to install it in a already built network (192.168.1.0/24) because I have some devices that I want to reach with SSL VPN.
I try to explain what I think to do:
- assign virtual IP to the USG
- NAT that IP to the real IP (internal network of the USG, for example LAN1)
- create rule to let user connect from the primary network to that IP
- configure VPN SSL to reach internal IP of the USG (with NAT rule from the primary modem)
I attach an image to explain the situation:
0
Accepted Solution
All Replies
-
If your modem router at 192.168.1.1 can do static route there is another way without double NAT.
0 -
Thank you @Zyxel_Can!
Everythings are clear!
@PeterUK: yes there is a modem router and I have access to it. What do you mean with another waY?
Thanks
0 -
Instead of SNAT 192.168.0.31 from 192.168.1.30 or with virtual IP's you static route on the modem router at 192.168.1.1 for 192.168.0.0/24 to 192.168.1.30 you then make a routing rule with Use IPv4 Policy Route to Overwrite Direct Route checked to go from incoming LAN1 to next hop gateway 192.168.1.1
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 130 Nebula Ideas
- 90 Nebula Status and Incidents
- 5.4K Security
- 171 USG FLEX H Series
- 256 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 235 Service & License
- 372 News and Release
- 77 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight