FLEX 500H NAT - VPN problem
![ZdenekB](https://us.v-cdn.net/6029482/uploads/defaultavatar/nN4PAQRO7TCNP.jpg)
![First Anniversary](https://us.v-cdn.net/6029482/uploads/badges/SJKCAIG91R5S.png)
![First Comment](https://us.v-cdn.net/6029482/uploads/badges/MBNFIRD87YVH.png)
I create NAT rule ( and rule works OK ):
but now when i use VPN conection ( windows vpn client ) and try connect to web in my LAN ( for example on IP 192.168.0.7 ) all my web traffic end on ip 192.168.100.210. When I turn NAT rule off all works fine.
All Replies
-
Hi @ZdenekB
What is the firmware version you are using? What is the VPN client's IP range? Do you have any Policy Route or static route settings? Thanks.
Share yours now!
0 -
Hi
firmware: V1.20(ABZH.0)client IP :
no policy or static route
Thanks
0 -
Slightly different setting like WAN3 and LAN subnets but not able to create your problem other then wrong zone for VPN in logs and able to do WAN3 to LAN for VPN traffic
0 -
I ran into this exact Problem yesterday.
If i set up a NAT-Rule from WAN to LAN, for Example for Port 443, all 443 Traffic trough an IPSec Tunnel lands there as well
Interface: ge1
Source-IP: any
External IP: any
Internal IP: [IP-of-Webserver]
Port Mapping Type: Service
External/Internal Service: httpsIf we have multiple internal Servers that run a service on 443, All traffic trough the IPSec-VPN Tunnel will be redirected to the one set by the NAT Rule
The IPSec Tunnel is assigned to the default IPSec_VPN Zone
Traffic trough the IPSEC VPN Tunnel might be treated as traffic from ge1, but assigned a different Zone, and since NAT Rules work on interfaces, not Zones this might be where the issue stems from.
I just made a workaround by changing the access from the internet to 4433 → forward to 443 since it's not used by the public, only for external access by workers from anywhere
If this was something that should be publicly available from anywhere, that would be a bigger issue for us.
0
Categories
- All Categories
- 413 Beta Program
- 2.3K Nebula
- 192 Nebula Ideas
- 87 Nebula Status and Incidents
- 5.3K Security
- 142 USG FLEX H Series
- 253 Security Ideas
- 1.3K Switch
- 75 Switch Ideas
- 993 Wireless
- 51 Wireless Ideas
- 6.1K Consumer Product
- 231 Service & License
- 362 News and Release
- 74 Security Advisories
- 23 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 101 About Community
- 67 Security Highlight