IPSEC vpn up, but no traffic only certain internet connection

Options
DeNino
DeNino Posts: 3
First Anniversary Friend Collector First Comment

Hello, everyone,
I have a connection problem with the IPSEC VPN.
i manage some networks with zyxel usg flex 200, on which i have configured the ipsec vpn. from my office i can connect to all of them without problems using ZyWALL IPSec VPN Client, while from home on some connections it's all ok and on others the vpn is up, but there is no traffic. i suppose it's a problem related to my isp and the remote ips is it possible?
i think the vpn is configured correctly as from my office or using my smartphone as a hotspt everything works fine.

i've searched online for many guides and solutions, but none have worked.

thanks to all.

Accepted Solution

  • DeNino
    DeNino Posts: 3
    First Anniversary Friend Collector First Comment
    Answer ✓
    Options

    Hi everyone, i found the problem, the ISP router in sites C and D (that is connected to the wan port of the firewalls) was using the same ip subnet for the LAN that i use at home, i changed it and now it works.

    thanks everyone for the support.

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,066  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @DeNino

    Welcome to the Zyxel community. While you are unable to access the internet through the VPN tunnel from your home, is there any blocked message that can be observed? Can you ping the firewall's intranet LAN clients normally? Are other people experiencing the same problem as you? Thanks.

  • DeNino
    DeNino Posts: 3
    First Anniversary Friend Collector First Comment
    Options

    hi @Zyxel_Jeff, thanks for your reply.
    i don't see any blocking messages, and on the ZyWALL IPSec VPN Client software the connection is stalibited and green, but i can't ping any clients on the other side.
    the strange thing is that if I connect from the office to the other sites A, B, C, or D the VPN is active and I reach the devices in all the sites. while from home even if the VPN is active on A, B, C, and D I only reach the devices in sites A and B, but not those in C and D.
    so I think the VPN configurations are right on all remote firewalls, and maybe it's a problem related to my ISP.
    I'm missing something, but I can't figure out what.

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,066  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @DeNino

    OK, thanks for your update. Please check the IPsec VPN related security policies and route settings on the USG Flex 200 to see if you have allowed the IPsec VPN client IP ranges to access sites C and D. Thanks.

  • DeNino
    DeNino Posts: 3
    First Anniversary Friend Collector First Comment
    Answer ✓
    Options

    Hi everyone, i found the problem, the ISP router in sites C and D (that is connected to the wan port of the firewalls) was using the same ip subnet for the LAN that i use at home, i changed it and now it works.

    thanks everyone for the support.

Security Highlight