Help with routing from site 1 to site 3 (site1==site2==site3)
All Replies
-
After setting it up here by locally you don't need the concentrator
Did all site to site with IKEv2 and doable even with dynamic IP by Site-to-site with Dynamic Peer
site A ping from 192.168.254.134 to site C 192.168.255.52
Site A USG60W
WAN2 dynamic IP
LAN1 192.168.254.129/255.255.255.128
VPN gateway to site B 192.168.254.1
VPN connection site-to-site
Nailed-Up
Gwtozywall110_local
local policy 192.168.254.128/26
remote policy 192.168.138.0/28
routing rule
Interface LAN1
destination address 192.168.255.48/28
next hop VPN tunnel
Tuneltozywall110_local
-----------------------------
Site B Zywall 110
OPT 192.168.254.1
VPN gateway to site A Dynamic Address
VPN connection Site-to-site with Dynamic Peer
GwtoUSG60W_local
local policy 192.168.138.0/28
remote policy 192.168.254.128/26
VPN gateway to site C 192.168.255.247
VPN connection Site-to-site
GWtoVPN300_local2
local policy 192.168.138.0/28
remote policy 192.168.255.48/28
routing rule
Tunnel TuneltoUSG60W_local
destination address 192.168.255.48/28
next hop VPN tunnel
TuneltoVPN300_local2
-----------------------------------
Site C VPN300
Ge3 192.168.255.247
Ge5 192.168.255.48 / 255.255.255.240
VPN gateway to site B 192.168.255.202
VPN connection Site-to-site
GWtozywall110_local2
local policy 192.168.255.48/28
remote policy 192.168.138.0/28
routing rule
Interface Ge5
destination address 192.168.254.128/26
next hop VPN tunnel
GWtozywall110_local2
0 -
Hi @OldFox,
1)Kindly check the VPN profile which connected site3 on site2 ,The local policy(phase2) shall involve site1 subnet.
2)Another solution. Concentrator can apply in your scenario.Please find following the handbook (Started At Page 87)
https://download.zyxel.com/ATP700/handbook/ATP700_ZLD5.20_Handbook.pdf
If the issue still persist,Could you share your all configuration in Private Message ? We would assist you to check.
Thank you
Kevin0 -
Zyxel_Kevin said:Hi @OldFox,
1)Kindly check the VPN profile which connected site3 on site2 ,The local policy(phase2) shall involve site1 subnet.
Currently I've switched to PLAN-B and did the following:
- switched from "Remote Access (Server Role)" to "Site-to-site with Dynamic Peer"
- switched to IKEv2 with certs auth.
- created another tunnel from site3 to site 1, so I have 3 tunnels now:
Site1
/ \
Site2 -- Site3
Thanks for your help guys!0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 271 USG FLEX H Series
- 274 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 389 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 74 Security Highlight