L2TP over IPSec Client (iOS, Windows, Android)
Hello all
via wizard i configured the vpn in subject.
I can connect I can see in the zyxel monitoring my vpn session with the Mac, but unfortunately I can't access or ping the local resources.
USG50 FLEX
WAN 192.168.1.200/255.255.255.0
L2TP IP Address Pool RANGE, 192.168.1.30-192.168.1.35
LAN1 IP 10.10.10.33
Can someone please help me?
Thanks
Regards
F.
All Replies
-
Hi @faye83,
Seems like your WAN and L2TP subnet are in the same subnet range. To avoid conflict, could you try to change the L2TP IP subnet first?
Zyxel Melen0 -
Hi Melen
Thank you for your help.
I changed L2TP IP subnet to 192.168.100.30-192.168.100.35 but I still have the same problem: I can't access or ping my nas. I thought maybe a Policy Route is needed but I don't know how to do it.Regards
F.
0 -
Melen I have one more piece of information: I can ping (and web login) the firewall port on the internal network 10.10.10.xxx (LAN1) but not the nas which is in the same network 10.10.10.yyyy
0 -
Hi @faye83,
This could be two reasons:
- The firewall security policy doesn't allow VPN traffic to the LAN. Below is an example that allows VPN traffic.
- The device doesn't allow ping. You need to check the NAS firewall rule.
Zyxel Melen0 -
Hi Melen,
In the local network I can ping the nas but with the vpn connection the ping and smb connection doesn't go. What do you suggest?
Thanks
Regards
F.
0 -
And other hosts on LAN1? Can you reach them? A printer or some other device.
Do you find some entry in log "access denied"?
What are your rules (in comparison to those posted by Zyxel Melen)?
0 -
Hi @faye83,
Since I'm unsure of your NAS firewall rules, it might allow ping with the same LAN and deny from other subnets. So, you need to check the NAS firewall rule.
Also, please check your firewall logs to see if there are any blocking logs. If so, please set security policy rules to allow the VPN traffic.
Zyxel Melen0 -
Hello all
thank you very much for your help!
The problem was the nas firewall blocking the connections.
Now works.
Kind regards
Regards
F.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 157 Nebula Ideas
- 106 Nebula Status and Incidents
- 5.9K Security
- 327 USG FLEX H Series
- 286 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 257 Service & License
- 400 News and Release
- 86 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 78 Security Highlight