VPN solution required
Accepted Solution
-
Hi @EB91,
In Local ID Type and Peer ID Type are used to identify the Zyxel Device during authentication.
IP - the Zyxel Device is identified by an IP address
DNS - the Zyxel Device is identified by a domain name
E-mail - the Zyxel Device is identified by the string specified in this field
Set Peer ID Type as Any to let the ZyWALL/USG does not require to check the identity content of the remote IPSec router.
If you use wizard to configure VPN tunnel between two USG110, the Peer ID Type is the Peer Gateway Address.
You can also choose DNS or E-mail as Peer ID Type in both VPN gateways and make them match with each other.
FritzBox (home office) -> Location B -> USG110 -> VPN tunnel -> USG110 -> location A (office where the server is located)
In your scenario, if the user at home office establishes VPN to Location B, you can create policy rules on both USG110 to allow the user at home office to access servers in location A.
If Home User using L2TP VPN to connect to Location B,
Location B
Incoming: Tunnel, L2TP_VPN_tunnel
Destination: subnet in Location A (Server’s in Location A)
Next-Hop: site to site VPN tunnel between two USG110
Location A
Source: subnet of Location A (Server’s in Location A)
Destination: L2TP subnet in location B
Next-Hop: site to site VPN tunnel between two USG110
If Home User using SSL VPN to connect to Location B, please see the FAQ article.
How do I allow SecuExtender clients to access servers in the remote site/company through VPN tunnel?
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community5
All Replies
-
Additional information, sorry for that:Every change I did was made at City "B" USG110.0
-
So both USG110 is locate at office in different location ?
Any VPN connected between USG110 now ?
What's the VPN client on your home ?
Which office you want to connect to ?
0 -
Thanks for you answer!- correct, a USG110 in location A and the other one in location B (both in germany)- between these two firewalls is an excisting vpn connection to each other, thats all- i dont have any vpn client yet at home, at first i want to make sure that anything is set correct.I want to connect to location A where our server and NAS is located but I dont know if it is enough to connect to my office (Location B ) or wether it is neccesary to create a vpn at location A as well.Configuration at the moment:Location B (my office) -> USG110 -> VPN tunnel -> USG110 -> location A (office where the server ist located).Future:FritzBox (home office) -> Location B -> USG110 -> VPN tunnel -> USG110 -> location A (office where the server ist located).
0 -
Hi @EB91,
In Local ID Type and Peer ID Type are used to identify the Zyxel Device during authentication.
IP - the Zyxel Device is identified by an IP address
DNS - the Zyxel Device is identified by a domain name
E-mail - the Zyxel Device is identified by the string specified in this field
Set Peer ID Type as Any to let the ZyWALL/USG does not require to check the identity content of the remote IPSec router.
If you use wizard to configure VPN tunnel between two USG110, the Peer ID Type is the Peer Gateway Address.
You can also choose DNS or E-mail as Peer ID Type in both VPN gateways and make them match with each other.
FritzBox (home office) -> Location B -> USG110 -> VPN tunnel -> USG110 -> location A (office where the server is located)
In your scenario, if the user at home office establishes VPN to Location B, you can create policy rules on both USG110 to allow the user at home office to access servers in location A.
If Home User using L2TP VPN to connect to Location B,
Location B
Incoming: Tunnel, L2TP_VPN_tunnel
Destination: subnet in Location A (Server’s in Location A)
Next-Hop: site to site VPN tunnel between two USG110
Location A
Source: subnet of Location A (Server’s in Location A)
Destination: L2TP subnet in location B
Next-Hop: site to site VPN tunnel between two USG110
If Home User using SSL VPN to connect to Location B, please see the FAQ article.
How do I allow SecuExtender clients to access servers in the remote site/company through VPN tunnel?
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community5 -
thanks for the reply and the information! You helped me a lot, I will check everything with my colleague!0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 152 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.8K Security
- 286 USG FLEX H Series
- 278 Security Ideas
- 1.5K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 251 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight