L2TP VPN traffic routing to VPN tunnel

Hi,

I have a Zyxel Flex 200 firewall, which I manage trough nebula. 

My Firewall has the ip 192.168.1.1 
L2TP vpn is set up to use 192.168.3.0/24

I'm in the process of setting up a VPN site to site tunnel to Azure and I need to be able to access the network on Azure. The network on Azure is: 172.10.1.0/24. The creation of the tunnel seems simple enough. 

How can I route L2TP traffic so that it work to both the 192.168.1.0/24 network (this works already by default) and the network behind the VPN tunnel on Azure (172.10.1.0/24)?




Accepted Solution

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,039  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Hello @PuuhaPete

    Welcome to Zyxel community. According to your requirement, you could configure a policy route as below: source IP is L2TP IP range and destination IP is remote site IP range, Type : VPN Traffic and the Next-Hop please choose that VPN tunnel.



    As for another question, once you establish L2TP on your device, all traffic will be passed through the L2TP tunnel. 
    Thanks.

All Replies

  • I tested some more and it seems that all of the internet traffic on the computer connecting through L2TP is routed through the L2TP tunnel.
    Is this correct?
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,039  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Hello @PuuhaPete

    Welcome to Zyxel community. According to your requirement, you could configure a policy route as below: source IP is L2TP IP range and destination IP is remote site IP range, Type : VPN Traffic and the Next-Hop please choose that VPN tunnel.



    As for another question, once you establish L2TP on your device, all traffic will be passed through the L2TP tunnel. 
    Thanks.
  • Thanks for your advice. 
    Do I also need to enable the Use VPN check box under Site-to-Site VPN for the 192.168.3.0 network?



  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,039  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    PuuhaPete said:
    Thanks for your advice. 
    Do I also need to enable the Use VPN check box under Site-to-Site VPN for the 192.168.3.0 network?



    The "Use VPN" switch means your local policy for the site-to-site VPN. According to your setting, the first priority local policy is lan1192.168.1.0/24. So, you won't enable the "Use VPN" switch on 192.168.3.0/24 and you still can use L2TP VPN and site-to-site VPN services. Thanks :) .

Nebula Tips & Tricks