IPSec tunnel VLAN to VLAN


All Replies
-
Each USG60 VLAN subnet must not be the same and might you try site to site?
0 -
PeterUK said:
Each USG60 VLAN subnet must not be the same and might you try site to site?
The VLAN's are different (192.168.81.0 and 192.168.82.0) I tried Site to site, but does only work for regular interfaces, not if you want to transfer only VLAN.
0 -
Site to site works with VLANs
site A with 192.168.81.0/24
local policy 192.168.81.0/24
remote policy 192.168.82.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.82.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
site B with 192.168.82.0/24
local policy 192.168.82.0/24
remote policy 192.168.81.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.81.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
firewall rules:
from WAN to Zywall protocol 50, UDP 500, 1701 and 4500
One side will need port forwarding for protocol 50, UDP 500, 1701 and 4500 the other side nailed up.
0 -
@nielsscheldeman what's firmware version are working on your device?
You may capture packets on VTI interface to monitor the traffic status.0
Categories
- 6.8K All Categories
- 1.4K Nebula
- 29 Nebula Ideas
- 38 Nebula Status and Incidents
- 3.9K Security
- 200 Security Ideas
- 723 Switch
- 30 Switch Ideas
- 601 WirelessLAN
- 8 WLAN Ideas
- 4.5K Consumer Product
- 98 Service & License
- 214 New and Release
- 38 Security Advisories
- 513 FAQ
- 236 Nebula FAQ
- 117 Security FAQ
- 74 Switch FAQ
- 65 WirelessLAN FAQ
- 5 Consumer Product FAQ
- Documents
- 30 Nebula Monthly Express
- 43 About Community
- 31 Security Highlight