Multiple subnets with one IPSec VPN?
Recently replaced rusty 100mb/s firewall with shiny new USG 60, to be able use new ISP tariff plan with 300 mb/s and still be able to use IPSec tunnels to another site
Scheme is fairly easy, so no drawings, sorry
Local site - USG 60
192.168.6.0/24 - tel subnet
192.168.9.0/24 - computers subnet
Remote site - Cisco ASA
192.168.5.0/24 - tel subnet
192.168.10.0/24 - computers subnet
192.168.30.0/24 - servers subnet
The deployment scenario from Zyxel KB describes connecting ONE local subnet to ONE remote subnet, but i need to access all remote subnets from my local subnets. Now IPSec working and connecting telephone subnets only.
From previous experience using cisco / dlink firewalls, this is usually achieved by creating groups of objects(subnets) and then using them in VPN parameters, but the Zyxel interface explodes the brain
Could you please direct me in the right direction. Straight googling leads to nowhere.
Step-by step instruction will be best solution
Would greatly appreciate any help!
Thanks!
Scheme is fairly easy, so no drawings, sorry
Local site - USG 60
192.168.6.0/24 - tel subnet
192.168.9.0/24 - computers subnet
Remote site - Cisco ASA
192.168.5.0/24 - tel subnet
192.168.10.0/24 - computers subnet
192.168.30.0/24 - servers subnet
The deployment scenario from Zyxel KB describes connecting ONE local subnet to ONE remote subnet, but i need to access all remote subnets from my local subnets. Now IPSec working and connecting telephone subnets only.
From previous experience using cisco / dlink firewalls, this is usually achieved by creating groups of objects(subnets) and then using them in VPN parameters, but the Zyxel interface explodes the brain
Could you please direct me in the right direction. Straight googling leads to nowhere.
Step-by step instruction will be best solution
Would greatly appreciate any help!
Thanks!
0
Accepted Solution
-
Hi,
USG doesn't support multiple traffic selectors.
So you can use route-based VPN(VTI), if ASA OS is 9.7 or above.
5
All Replies
-
Hi,
USG doesn't support multiple traffic selectors.
So you can use route-based VPN(VTI), if ASA OS is 9.7 or above.
5
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight