Connect USG Flex 200 to zywall 110

jkocovski
jkocovski Posts: 5  Freshman Member
First Comment Friend Collector

Hi there,

i`m not a pro but i have to connect two Firewalls via WAN Ports. Setup is as follow:

USG Flex 200

WAN 1 - Connection to World (ETH to ISP)

WAN 2 - 192.168.10.1 - 255.255.255.252 - gw 192.168.10.2 (to zywall 110)

LAN 1 - 192.168.178.0/24

Routing set for Incoming any - source any - Destination 10.1.1.0/24 - next hop WAN 2 no nat

Zywall 110WAN 1 - connection to the world (PPP to ISP)WAN 2 - 192.168.10.2 - 255.255.255.252 - gw 192.168.10.1 (to usg flex 200)LAN 1 - 10.1.1.0/24Routing set for Incoming any - source any - Destination 192.168.178.0/24 - next hop WAN 2 no natBoth firewalls are connected via eth directly. they are in different rooms and support different working units. now i need to connect from any LAN to any LAN and i failed :-/The usg Flex can ping can ping their own interface AND the remote (192.168.10.1).the zywall 110 can ping their own interface and NOT the remote (192.168.10.2).IMHO what i did should be enough but as far as the result said it looks like not. Does you guys see anything i`m doing wrong or messed up?Thanks a lot for helping.

All Replies

  • Xydocq
    Xydocq Posts: 30  Freshman Member
    First Comment First Answer Friend Collector
    edited January 6

    hi @jkocovski

    your setup looks like this: Internet > Zywall 110 > USG Flex 200

    USG Flex 200 will block all incoming traffic on WAN port, it will also not respond to a ping.

    Might be best to replace the Zywall 110 with the USG Flex 200 and use a layer 3 switch instead of another firewall.

  • jkocovski
    jkocovski Posts: 5  Freshman Member
    First Comment Friend Collector

    @Xydocq nope. It`s basicaly a 2 company setup. Same floor, different compnays and they have both own internet providers but want to share some ressources. So i can`t replaxe anything and i will have to live with what is there.

  • Xydocq
    Xydocq Posts: 30  Freshman Member
    First Comment First Answer Friend Collector
    edited January 7

    then Site-2-Site VPN would be the way to go.

    Maybe you're able to establish a VPN-connection on WAN2 of the USG Flex 200 to the Zywall 110.