FLEX 500H NAT - VPN problem
I create NAT rule ( and rule works OK ):
but now when i use VPN conection ( windows vpn client ) and try connect to web in my LAN ( for example on IP 192.168.0.7 ) all my web traffic end on ip 192.168.100.210. When I turn NAT rule off all works fine.
All Replies
-
Hi @ZdenekB
What is the firmware version you are using? What is the VPN client's IP range? Do you have any Policy Route or static route settings? Thanks.
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0 -
Hi
firmware: V1.20(ABZH.0)client IP :
no policy or static route
Thanks
0 -
Slightly different setting like WAN3 and LAN subnets but not able to create your problem other then wrong zone for VPN in logs and able to do WAN3 to LAN for VPN traffic
0 -
I ran into this exact Problem yesterday.
If i set up a NAT-Rule from WAN to LAN, for Example for Port 443, all 443 Traffic trough an IPSec Tunnel lands there as well
Interface: ge1
Source-IP: any
External IP: any
Internal IP: [IP-of-Webserver]
Port Mapping Type: Service
External/Internal Service: httpsIf we have multiple internal Servers that run a service on 443, All traffic trough the IPSec-VPN Tunnel will be redirected to the one set by the NAT Rule
The IPSec Tunnel is assigned to the default IPSec_VPN Zone
Traffic trough the IPSEC VPN Tunnel might be treated as traffic from ge1, but assigned a different Zone, and since NAT Rules work on interfaces, not Zones this might be where the issue stems from.
I just made a workaround by changing the access from the internet to 4433 → forward to 443 since it's not used by the public, only for external access by workers from anywhere
If this was something that should be publicly available from anywhere, that would be a bigger issue for us.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight