IPSec tunnel VLAN to VLAN
All Replies
-
Each USG60 VLAN subnet must not be the same and might you try site to site?
0 -
PeterUK said:
Each USG60 VLAN subnet must not be the same and might you try site to site?
The VLAN's are different (192.168.81.0 and 192.168.82.0) I tried Site to site, but does only work for regular interfaces, not if you want to transfer only VLAN.
0 -
Site to site works with VLANs
site A with 192.168.81.0/24
local policy 192.168.81.0/24
remote policy 192.168.82.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.82.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
site B with 192.168.82.0/24
local policy 192.168.82.0/24
remote policy 192.168.81.0/24
routing rule
incoming interface
member the VLAN
destination 192.168.81.0/24
next hop
type VPN Tunnel
VPN tunnel the zone for the tunnel
firewall rules:
from WAN to Zywall protocol 50, UDP 500, 1701 and 4500
One side will need port forwarding for protocol 50, UDP 500, 1701 and 4500 the other side nailed up.
0 -
@nielsscheldeman what's firmware version are working on your device?
You may capture packets on VTI interface to monitor the traffic status.0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight