USG 110 SSL client multi VPN
Best Answers
-
The IP address space of your SSL VPN clients is 192.168.100.100-120
So if your are using policy-based IPSec site-to-site tunnel.
The VPN connection setting of local poly in HQ and remote policy need to include the IP address space of SSL VPN clients.
5 -
Hi @Ondrej
Welcome to Zyxel community.

You topology:
SSL Client(192.168.100.100)--------HQ(HQ subnet)========[VPN]======Branch(Branch Subnet)
As your scenario, SSL VPN client is able access to HQ subnet but unable access to branch subnet.
You can go to make sure if you have added routing for SSL VPN client on both of devices.
(1) On HQ device. The “branch subnet” have to add into network list of SSL VPN.

(2) Add policy route on HQ device.
Destination: Branch subnet, NextHop: VPN tunnel.

(3) Add policy route on Branch device.
a. Incoming: ZyWALL, Destination IP: SSL VPN Pool. NextHop: VPN (It is for access to Branch ZyWALL)
b. Incoming: any, Destination IP: SSL VPN Pool, NextHop: VPN (It is for access to branch subnet)

5
All Replies
-
The IP address space of your SSL VPN clients is 192.168.100.100-120
So if your are using policy-based IPSec site-to-site tunnel.
The VPN connection setting of local poly in HQ and remote policy need to include the IP address space of SSL VPN clients.
5 -
Hi @Ondrej
Welcome to Zyxel community.

You topology:
SSL Client(192.168.100.100)--------HQ(HQ subnet)========[VPN]======Branch(Branch Subnet)
As your scenario, SSL VPN client is able access to HQ subnet but unable access to branch subnet.
You can go to make sure if you have added routing for SSL VPN client on both of devices.
(1) On HQ device. The “branch subnet” have to add into network list of SSL VPN.

(2) Add policy route on HQ device.
Destination: Branch subnet, NextHop: VPN tunnel.

(3) Add policy route on Branch device.
a. Incoming: ZyWALL, Destination IP: SSL VPN Pool. NextHop: VPN (It is for access to Branch ZyWALL)
b. Incoming: any, Destination IP: SSL VPN Pool, NextHop: VPN (It is for access to branch subnet)

5 -
0
Categories
- All Categories
- 440 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 528 USG FLEX H Series
- 331 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 50 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.6K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member

ping BR1,2,3.
Master Member
Zyxel Employee