IPSec tunnel VLAN to VLAN
All Replies
-
Each USG60 VLAN subnet must not be the same and might you try site to site?
0 -
PeterUK said:
Each USG60 VLAN subnet must not be the same and might you try site to site?
The VLAN's are different (192.168.81.0 and 192.168.82.0) I tried Site to site, but does only work for regular interfaces, not if you want to transfer only VLAN.
0 -
Site to site works with VLANs
site A with 192.168.81.0/24
local policy 192.168.81.0/24
remote policy 192.168.82.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.82.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
site B with 192.168.82.0/24
local policy 192.168.82.0/24
remote policy 192.168.81.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.81.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
firewall rules:
from WAN to Zywall protocol 50, UDP 500, 1701 and 4500
One side will need port forwarding for protocol 50, UDP 500, 1701 and 4500 the other side nailed up.
0 -
@nielsscheldeman what's firmware version are working on your device?
You may capture packets on VTI interface to monitor the traffic status.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight