Accessing shared folders over IPSec Site to site VPN

Options
2»

All Replies

  • Davidcloude2023
    Davidcloude2023 Posts: 12 image  Freshman Member
    First Comment Friend Collector
    edited March 2023
    Options

    that is the problem! i dont get the logs at all, i disabled the firewall on my ISP router for sure and nothing. i have included the screenshot from my policy control rules.

    Thank you for your time.

    The ipsec site to site vpn gives that the connected is established.

    Tunnel [GW_To_OldOffice:Con_To_OldOffice:0x6884d946] built successfully


    Office 2 (New_Office):

    firewall rules.png

    Office1 routing:

    Office1_Routing.PNG



    Office2 routing:

    Office2_Routing.PNG
  • Davidcloude2023
    Davidcloude2023 Posts: 12 image  Freshman Member
    First Comment Friend Collector
    Options

    is it possible that ESP packets are getting blocked?

  • PeterUK
    PeterUK Posts: 4,542 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited March 2023
    Options

    Yes that could be one reason because you don't have either USG having the WAN IP behind other NAT routers that you need to forward ports.

    Have you a rule to allow inbound UDP port 500, 1701, 4500 and protocol 50 from WAN to Zywall?

  • Davidcloude2023
    Davidcloude2023 Posts: 12 image  Freshman Member
    First Comment Friend Collector
    Options

    i have no rules set and not only the one in this picture on both zyxel devices. i can see that AH and ESP are in allow_from_ wan to zywall service group.

    i have 4500 and 500 and 1701 ports forwarded in the isp router to test if it works but i have the same results!.

    is it possible if you have time that you can connect to me through teamviewer or privatly. thank you for taking much of your time.

    Untitled Image
  • Davidcloude2023
    Davidcloude2023 Posts: 12 image  Freshman Member
    First Comment Friend Collector
    Options

    Peter fixed and solved the routing problems. 🙏 thank you

  • ionelpanciu
    ionelpanciu Posts: 3 image  Freshman Member
    First Comment
    Options


    Hello. I have the same problem, only that I have IPsec site-to-site but in a LAN. Class 1.0 so I can connect with 5.0. Connectivity is through 2 antennas that are part of class 1.0. I managed to do site-to-site VPN but I can't see the computers from one building in another class.

    If you can help me, that would be great. Thank you