Routing between different interfaces / vlan

alexia_net
alexia_net Posts: 9
First Comment
edited April 2021 in Security

Hello.

I have kind a strange issue with my Zyxel usg 40. I cannot do routing between different vlans on it.

It must be a configuration issue I am missing.

So I have a router which acts as DHCP - 192.168.1.0 /24

One PC (192.168.1.200) is connected into the router (192.168.1.1). And the WAN port of the Zyxel fw is connected into the router. So all of these are on the same network. PING works fine, including from the PC to the Zyxel fw (192.168.1.50)

On the Zyxel I have created, on LAN 1, a VLAN 6 with gateway 192.168.6.1. And there is as switch befind this interface.

I try to ping from 192.168.1.200 the vlan 6 gateway, 192.168.6.1 and the switch, 192.168.6.2.

But it does not work. I have put rules in place, saying that from WAN I should be able to ping LAN1 and Zywall / LAN1 gateway.

But I do not get any reply.

Any idea why?

Best regards!

Accepted Solution

  • alexia_net
    alexia_net Posts: 9
    First Comment
    Answer ✓

    Hello. 

    There is a problem with my router, pointing towards the firewall where vlan 6 is. 

    I have configured my pc to use the firewall (192.168.1.50) as gateway and it is working now. I have to check that router.

    Thank you all for your replies. 

    Best regards!

All Replies

  • goto73
    goto73 Posts: 1
    First Comment

    I have the same issue with Zyxzl SGB3600.

  • PeterUK
    PeterUK Posts: 2,655  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited July 2019

    Have you given your VLAN a zone like VLAN6 and not LAN1?

    Or make a firewall rule from LAN1 to LAN1 if zone is LAN1

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,426  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @alexia_net

    In this network topology, the USG looks like run as routing mode. You need to disable snat on USG, and add static on router.

    Configuration: 

    1) Disable “Default SNAT” on “CONFIGURATION > Network > Interface > Trunk > show advanced Settings”

    2) Add static route on router.

    192.168.6.1 255.255.255.0 to 192.168.1.50

  • alexia_net
    alexia_net Posts: 9
    First Comment
    Answer ✓

    Hello. 

    There is a problem with my router, pointing towards the firewall where vlan 6 is. 

    I have configured my pc to use the firewall (192.168.1.50) as gateway and it is working now. I have to check that router.

    Thank you all for your replies. 

    Best regards!

Security Highlight