UAG4100 LAN2 usage

hgg
hgg Posts: 4  Freshman Member
First Comment Friend Collector First Anniversary
edited April 2021 in Security
Hi,

I have a UAG4100 connected to two lans. The final client lan, lan1 works as expected. However I'm not able to reach the UAG4100 from lan2. I'm able to ping from the UAG4100 to lan2, but not the other way around. As far as I can see both lans have similar configuration:



What am I missing here?

Thank you,
Regards,
Helder Guerreiro

Comments

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @hgg,
    Device access from Lan2, the packets should hit the security rule#7 "from Lan 2 to Device". The rule is proper setting from your screen shot, it could be something wrong on other configuration.
    You can check the zone setting first on "Configuration > Object > Zone", make sure "LAN2 zone group" have member "lan2".
  • hgg
    hgg Posts: 4  Freshman Member
    First Comment Friend Collector First Anniversary
    Hi @Zyxel_Cooldia,

    I have the default configuration for Object → Zone:

    I think this is correct.

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    edited May 2018
    Hi @hgg,
    Can you do one more test, ping from lan2 subnet host to lan2 interface IP, and packets capture on lan2 interface.Here we would like to know does the UAG lan2 receive the packets from lan2 subnet host.
    If it is still fail to access from lan2, please send me your configuration file via private message.

    CLI packets trace:
    Router> packet-trace interface lan2

Security Highlight