USGFLEX 200H - VPN IPSec Remote Access Local Network

hexos
hexos Posts: 13  Freshman Member
Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - WLAN Zyxel Certified Network Engineer Level 1 - Security First Comment

Hello,

[USG FLEX 200H] We use IPSec VPN to provide remote access to two local networks (192.168.100.0/24 & 192.168.106.0/24)

The only way we found to authorize access to these two networks is using a larger subnet :

But that's not clean. Is there a way to authorize only two separate networks and not all the range ?

Thank you !

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,085  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @hexos,

    You can try adding a security policy to block the access.

    Below is an example. My remote access VPN is in "IPSec_VPN" zone, and I create some subnet objects for addressing the traffic flow so I can configure a specific deny rule.

    Zyxel Melen


  • hexos
    hexos Posts: 13  Freshman Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - WLAN Zyxel Certified Network Engineer Level 1 - Security First Comment

    Hi @Zyxel_Melen

    Thank you for your quick response. In my case yes, but if the two networks are very far ?

    Example : Network 1 is 10.130.0.0/24 and network 2 is 192.168.100.0/24

    In future releases, could it be possible to add multiple networks like it can be done with SSL VPN :

    Thanks

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,085  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @hexos,

    Thanks for pointing. Let me ask our product team if IPSec remote access VPN will support it. I will keep you posted.

    Zyxel Melen