IPSec tunnel VLAN to VLAN





All Replies
-
Each USG60 VLAN subnet must not be the same and might you try site to site?
0 -
PeterUK said:
Each USG60 VLAN subnet must not be the same and might you try site to site?
The VLAN's are different (192.168.81.0 and 192.168.82.0) I tried Site to site, but does only work for regular interfaces, not if you want to transfer only VLAN.
0 -
Site to site works with VLANs
site A with 192.168.81.0/24
local policy 192.168.81.0/24
remote policy 192.168.82.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.82.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
site B with 192.168.82.0/24
local policy 192.168.82.0/24
remote policy 192.168.81.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.81.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
firewall rules:
from WAN to Zywall protocol 50, UDP 500, 1701 and 4500
One side will need port forwarding for protocol 50, UDP 500, 1701 and 4500 the other side nailed up.
0 -
@nielsscheldeman what's firmware version are working on your device?
You may capture packets on VTI interface to monitor the traffic status.0
Categories
- 8.5K All Categories
- 1.6K Nebula
- 71 Nebula Ideas
- 57 Nebula Status and Incidents
- 4.5K Security
- 226 Security Ideas
- 983 Switch
- 46 Switch Ideas
- 878 WirelessLAN
- 22 WLAN Ideas
- 5.2K Consumer Product
- 157 Service & License
- 280 News and Release
- 59 Security Advisories
- 13 Education Center
- 580 FAQ
- 263 Nebula FAQ
- 160 Security FAQ
- 76 Switch FAQ
- 74 WirelessLAN FAQ
- 7 Consumer Product FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 69 About Community
- 46 Security Highlight