UAG4100 LAN2 usage

hgg
hgg Posts: 4
First Comment Friend Collector First Anniversary
 Freshman Member
edited April 2021 in Security
Hi,

I have a UAG4100 connected to two lans. The final client lan, lan1 works as expected. However I'm not able to reach the UAG4100 from lan2. I'm able to ping from the UAG4100 to lan2, but not the other way around. As far as I can see both lans have similar configuration:



What am I missing here?

Thank you,
Regards,
Helder Guerreiro

Comments

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,055
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments
     Guru Member
    Hi @hgg,
    Device access from Lan2, the packets should hit the security rule#7 "from Lan 2 to Device". The rule is proper setting from your screen shot, it could be something wrong on other configuration.
    You can check the zone setting first on "Configuration > Object > Zone", make sure "LAN2 zone group" have member "lan2".
  • hgg
    hgg Posts: 4
    First Comment Friend Collector First Anniversary
     Freshman Member
    Hi @Zyxel_Cooldia,

    I have the default configuration for Object → Zone:

    I think this is correct.

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,055
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments
     Guru Member
    edited May 2018
    Hi @hgg,
    Can you do one more test, ping from lan2 subnet host to lan2 interface IP, and packets capture on lan2 interface.Here we would like to know does the UAG lan2 receive the packets from lan2 subnet host.
    If it is still fail to access from lan2, please send me your configuration file via private message.

    CLI packets trace:
    Router> packet-trace interface lan2

Security Highlight