USG Flex 100 Problem with Content Filter, Signature Updates, etc... etc...

2»

All Replies

  • Policy control: looks to me like a Zywall (Device?) to WAN route is missing here:



  • OK, found it, it's the above NAT necessary for the USG WAN being in a NAT'ed network, how do I fix this?
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @stepgilb,
    Flex 100 wan interface is 192.168.178.X/24.
    Please remove NAT rule from FLEX100. the IP 87.191.X.X is not FLEX 100 interface IP.
  • Sure, but without that rule I can't get L2TP/IPSEC to work. I guess this rule needs to be limited...
  • stepgilb
    stepgilb Posts: 12
    First Comment
    Answer ✓
    OK, got it to work, limited the Source IP to the LAN 2 subnet. L2TP/IPSec and Zywalll Device routing works.

Security Highlight