Why no traffic pass through the tunnel as it's established?

Zyxel_James
Zyxel_James Posts: 663  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

Question: Why no traffic pass through the tunnel as it's established?

Answer:

  • 1.Make sure to allow ESP from WAN to Device. Without allowing ESP, the firewall cannot unencrypt encapsulated packets.
  • Check Policy Route/Static Route. Check if any policy routes or static routes that could interfere with routing traffic into the VPN tunnel. These routes may divert the traffic elsewhere, preventing it from entering the VPN tunnel.

  • Make sure there is no Subnet Overlap
    With overlapping subnets, VPN traffic might be unintentionally routed internally instead of through the VPN tunnel. Ensure that the VPN traffic is correctly directed towards the tunnel to avoid such issues.
    You can go to Maintenance -> Packet Flow Explore -> Routing Status to check all routes.

Tagged: