VPN : remote access to 2 sites

crsdg
crsdg Posts: 5
First Comment

Hello,
I have a company who has 2 sites.

I want create a mobile VPN (i already have) who can connect these 2 sites with only one configuration with VPN include in Windows (i don't want use secuextender).
Do you have a solution ?
Site 1 and Site 2 are linked with vpn ipsec site-to-site
I tried to connect laptop to Site1 (with vpn ikev2 and it works) and try to access at the site 2 with a routing but doesn't work.

thanks

All Replies

  • PeterUK
    PeterUK Posts: 3,326  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited January 12

    Do the sites have non over lapping subnets that are enabled

  • crsdg
    crsdg Posts: 5
    First Comment

    where can i check this?

    (sorry i'm french)

  • PeterUK
    PeterUK Posts: 3,326  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited January 12

    like if you have on site 1 you use 192.168.1.0/24 and don't use 192.168.2.0/24 but is enabled and on site 2 use 192.168.2.0/24 and don't use 192.168.1.0/24 but is enabled this would cause a problem.

    And the subnet of the VPN as server role needs to be on its own subnet

  • crsdg
    crsdg Posts: 5
    First Comment

    in my site 1 i use 192.168.120.0/24 and this subnet is not present on the site 2.

    in my site 2 i use 172.16.16.0 /24 and this subnet is not present on the site 1.

    the subnet of vpn client is 192.168.10.0/24.

  • PeterUK
    PeterUK Posts: 3,326  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited January 12

    If you got the firewall rule to go from vpn client zone to site to site zone it should work.

    Is “Use Policy Route to control dynamic IPSec rules” unchecked?

    Try making a routing rule on site 1 with

    incoming Tunnel

    member VPN of client

    destination 172.16.16.0 /24

    next hop VPN Tunnel

    tunnel of site to site

    site 2 might need changing too with a routing rule to know where to send 192.168.10.0/24 back down the site to site tunnel

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,206  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Hello @crsdg

    Welcome to the Zyxel community. May we know your problem is resolved? If none, could you provide the remote Web-GUI to let us check it? We will send a private message to you later, please check your inbox. Thanks.


    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

  • crsdg
    crsdg Posts: 5
    First Comment

    Many thanks problem is solved

Security Highlight