Trouble Configuring Client-To-Site VPN with IKEv2 and USG40

rdvasil1
rdvasil1 Posts: 2  Freshman Member

I'm trying to setup a Client-To-Site VPN with a USG40 Host using IKEv2 and a Microsoft VPN client. I've followed the instructions in the guide - [ZyWALL/USG] How to set up a Client-to-Site VPN (Configuration
Payload/DHCP) connection using IKEv2

I've successfully connected from the remote client to the Host site and the client receives an IP address from the pool. However, I cannot access any resources on the host network, cannot ping the host router or any IP. The Windows client shows connected and packets sent but none received. The USG40 Monitor shows a VPN connection and packets received but none sent.

I'm assuming it's a NAT or Policy problem, but not sure where to look

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @rdvasil1,

    May I know if your security policy allows the VPN to access your LAN interface?

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited February 21

    Do both site have different LAN subnets you are trying to access?

    You maybe need a routing rule at the top of the list like

    incoming LAN1
    destination subnet of the other site
    next hop VPN tunnel

    Then a policy rule from LAN1 to VPN zone

    the other side might also need a routing rule