Two usg 310 vpn ipsec site-to-site

Options
neilos2015
neilos2015 Posts: 6
First Comment
edited April 2021 in Security
Hello I have two usg 310 and I have success connect my two office with a vpn ipsec, everything ok but when I add a dmz on another interface with another range ip (internal) the vpn still connect but the device stop to dialogate. Why? Can someone help me?

All Replies

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,367  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @neilos2015  

    The traffic transmitting between 2 USG VPN tunnel are worked by routing table.

    It may effects by routing/ policy control rules.

    So you can check:

    (1)   Does new IP address is conflicted in your USGs ?

    (2)   Does VPN traffic is blocked by policy control rules?

    (3)   Go to Maintenance > Packet Flow Explore and check if any routing effects to your VPN tunnel.


    Stanley

Security Highlight