USG200 - VPN on one LAN port
thisisliam
Posts: 10
Hi All
I'm considering upgrading to a USG200 to create a site-to-site VPN between two countries ("A" & "B"). Only one device on my network (Location "B") requires the site to site VPN and must have an IP address from Location "A" (abroad), the rest of the network can remain by default on the local network in Location "B". However, I'd like to have the option, if necessary, to add more devices to the Location "A" network from Location "B" down the road.
In order to avoid using two routers at each location and opening up ports for the VPN to work I am interested if I can use the USG200 as my primary router, use my existing router in bridge-mode to create the WiFi network from one of the USG200 LAN ports, and assign the site-to-site VPN to another LAN port on the USG200, which in turn can have a switch attached if need be.
Apologies if this is a "n00b" question. I appreciate your patience with any explaining.
I'm considering upgrading to a USG200 to create a site-to-site VPN between two countries ("A" & "B"). Only one device on my network (Location "B") requires the site to site VPN and must have an IP address from Location "A" (abroad), the rest of the network can remain by default on the local network in Location "B". However, I'd like to have the option, if necessary, to add more devices to the Location "A" network from Location "B" down the road.
In order to avoid using two routers at each location and opening up ports for the VPN to work I am interested if I can use the USG200 as my primary router, use my existing router in bridge-mode to create the WiFi network from one of the USG200 LAN ports, and assign the site-to-site VPN to another LAN port on the USG200, which in turn can have a switch attached if need be.
Apologies if this is a "n00b" question. I appreciate your patience with any explaining.
0
All Replies
-
If set up correctly (Trigger port, VPN triggered by outbound rule), you do not need to make any changes regardless of the number of devices in your local subnet. The USG device will either run a permanent VPN connection or a triggered VPN connection (depending on your practical VPN needs).
It does not matter if you only have one computer or several computers, the VPN tunnel will run as long as you have set it to be open. You just define that your entire subnet (LAN) on your side has access to the VPN port and tunnel. Number of computers is irrelevant as long as LAN has access.0 -
smb_corp_user said:If set up correctly (Trigger port, VPN triggered by outbound rule), you do not need to make any changes regardless of the number of devices in your local subnet. The USG device will either run a permanent VPN connection or a triggered VPN connection (depending on your practical VPN needs).
It does not matter if you only have one computer or several computers, the VPN tunnel will run as long as you have set it to be open. You just define that your entire subnet (LAN) on your side has access to the VPN port and tunnel. Number of computers is irrelevant as long as LAN has access.0 -
smb_corp_user said:If set up correctly (Trigger port, VPN triggered by outbound rule), you do not need to make any changes regardless of the number of devices in your local subnet. The USG device will either run a permanent VPN connection or a triggered VPN connection (depending on your practical VPN needs).
It does not matter if you only have one computer or several computers, the VPN tunnel will run as long as you have set it to be open. You just define that your entire subnet (LAN) on your side has access to the VPN port and tunnel. Number of computers is irrelevant as long as LAN has access.
Hello @thisisliam
The answer is yes, while you create a site-to-site VPN on Zyxel firewalls, you need to define their remote and local policies which means describing the remote and local subnet between each other, as in the below example.
VPN connection settings of the Headquarter site.
VPN connection settings of the Branch site.
About the detailed site-to-site VPN settings, you could refer to the below guide links:
An example of Site to Site VPN
IPSec VPN Site To Site
Thanks.
See how you've made an impact in Zyxel Community this year!
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 149 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 263 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight