Configuration VPN - other subnetwork

terry1996 Posts: 2
First Comment
edited April 2021 in Security
Hi, It is my 1st post on this forum, so please be patient :-)
I want to buy Zyxel USG 60 with VPN L2TP/IPSec

I have a plan of topology:

On the topology we can see zyxel firewall, switch L3 cisco, 3x cisco l2 switches and serwer FTP with DHCP, Win Serwer 2016, Active Directory. Serwer belong to VLAN 10.

To Switches L2 I connect some vlans.
Switch L3 is default gateway for all vlans (on int vlan 10, int vlan 20 etc.)

Between Switch L3 and firewall I have subnetwork .1 is zyxel address .2 is Switch L3 physicall address. 

Vpn is configuring to connect android mobile devices. I want to share for them other network than e.g. and Zyxel should be a DHCP for mobile vpn clients.

Can I do it with zyxel usg 60?

Or maybe I should to download other OS ?

All Replies

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @terry1996

    After established L2TP tunnel, USG will provide an address to client.  (the IP address pool configured in L2TP VPN setting) 

    Then you can add policy route for L2TP client:

    Source: L2TP_Pool, Destination:, NextHop: Switch IP(, SNAT: none.

    Of cause you have to add the routing on your switch that for packets back to L2TP client.

    e.g, Destination: L2TP_Pool, NextHop: USG interface(

  • thank U very much
    I am reading a lot and its and Ur comment helps me :-)

Security Highlight