[NEBULA] NSG50 L2TP VPN port failed

Matthieu
Matthieu Posts: 6
First Comment
edited April 2021 in Nebula
hello
My VPN is ok but i can't connect a phone software 
i can ping my AUTOCOM 
i can access to the website (port 80) 
but i can't connect to the 69 UDP port 

and i don't find where is the vpn firewall

thanks

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 590
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers 500 Comments
     Guru Member
    Welcome to Nebula community!!
    Do you mean you can ping your phone (Autocom) but cannot connect it and also got trouble on UDP 69 of TFTP service (but can access it with HTTP?)
    Also, may I know what's your phone software service using(TCP/UDP or multicast)? Please share your scenario for us. =)

    Chris
  • hi

    the problem 
    i can connect to autocom with http and ping 
    but when alcatel lucent soft phone want to connect he said connection failed

    and in the autocom log i can read failed connect with the ip adresse 192.168.0.1 but it's the  firewall  adress and not the client adress

    the autocom don't receve the good adress
    and i don't understand why

    firewall adress 192.168.0.1
    autocom adress 192.168.0.246
    client adress 192.168.4.1
  • Zyxel_Chris
    Zyxel_Chris Posts: 590
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers 500 Comments
     Guru Member
    Hi @Matthieu
    The reason of this problem is because of our L2TP will auto create the policy route for outgoing traffic (to Internet) hence it will use the SNAT, I'll suggest to add the policy route to resolve this issue as following screenshot, navigate to the Gateway>Configure>Policy route
    The select the type as "intranet traffic" the source IP will be your client and the destination will be the server IP. Hope it can help

    cheers!  =)

    Chris
  • thanks for the answers
    i want to test but 
    in my admin web site i don't have the same page

  • Zyxel_Chris
    Zyxel_Chris Posts: 590
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers 500 Comments
     Guru Member
    Hello @Matthieu
    Please be aware that the policy route type is "Intranet Traffic"
    Chris
  • thanks a lot it's ok

Nebula Tips & Tricks