Accessing another site from mobile tunnel

Options
Marcusgtd
Marcusgtd Posts: 1
edited April 2021 in Security
I have a site to site VPN setup between two USG20-VPN's.

Headquarters - 10.72.177.0/24
Branch Office - 10.72.188.0/24

I also host a VPN for mobile users at each office.

Mobile to Headquarters Tunnel - 10.72.10.0/24
Mobile to Branch Office Tunnel - 10.72.20.0/24


Computers in each office can reach each other (10.72.177.0 - 10.72.188.0), but I would like a mobile laptop connected to the Branch Office Tunnel on 10.72.20.0 to be able to reach computers on the Headquarters network (10.72.177.0).

Thank you. 

All Replies

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,374  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Marcusgtd

    You can use policy route to realized your scenario and both of device must be Site to Site VPN tunnel.

    (10.72.177.0/24)HQ=====[VPN]=====Branch(10.72.188.0/24)------L2TP(10.72.20.0/24)

    After client established tunnel to branch will received 10.72.20.0/24 IP address. And then add policy route on both of device. 

    On Branch device add policy route:


    On HQ device add policy route:


Security Highlight