L2TP VPN traffic routing to VPN tunnel

Hi,

I have a Zyxel Flex 200 firewall, which I manage trough nebula. 

My Firewall has the ip 192.168.1.1 
L2TP vpn is set up to use 192.168.3.0/24

I'm in the process of setting up a VPN site to site tunnel to Azure and I need to be able to access the network on Azure. The network on Azure is: 172.10.1.0/24. The creation of the tunnel seems simple enough. 

How can I route L2TP traffic so that it work to both the 192.168.1.0/24 network (this works already by default) and the network behind the VPN tunnel on Azure (172.10.1.0/24)?




Accepted Solution

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,206  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    Answer ✓
    Hello @PuuhaPete

    Welcome to Zyxel community. According to your requirement, you could configure a policy route as below: source IP is L2TP IP range and destination IP is remote site IP range, Type : VPN Traffic and the Next-Hop please choose that VPN tunnel.



    As for another question, once you establish L2TP on your device, all traffic will be passed through the L2TP tunnel. 
    Thanks.


    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

All Replies

  • I tested some more and it seems that all of the internet traffic on the computer connecting through L2TP is routed through the L2TP tunnel.
    Is this correct?
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,206  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    Answer ✓
    Hello @PuuhaPete

    Welcome to Zyxel community. According to your requirement, you could configure a policy route as below: source IP is L2TP IP range and destination IP is remote site IP range, Type : VPN Traffic and the Next-Hop please choose that VPN tunnel.



    As for another question, once you establish L2TP on your device, all traffic will be passed through the L2TP tunnel. 
    Thanks.


    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

  • Thanks for your advice. 
    Do I also need to enable the Use VPN check box under Site-to-Site VPN for the 192.168.3.0 network?



  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,206  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    PuuhaPete said:
    Thanks for your advice. 
    Do I also need to enable the Use VPN check box under Site-to-Site VPN for the 192.168.3.0 network?



    The "Use VPN" switch means your local policy for the site-to-site VPN. According to your setting, the first priority local policy is lan1192.168.1.0/24. So, you won't enable the "Use VPN" switch on 192.168.3.0/24 and you still can use L2TP VPN and site-to-site VPN services. Thanks :) .


    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

Nebula Tips & Tricks