USG FLEX 100H: ICMP between LAN1_SUBNET and LAN2_SUBNET

hexxit
hexxit Posts: 2  Freshman Member

With standard-configuration I can ping from LAN1_SUBNET to LAN2_SUBNET. Networks are 192.168.10.0/23 an 192.168.178.0/23. Both SUBNETS are in the internal_LAN Group.

ICMP from Clients in the LAN1_SUBNET to the LAN2_SUBNET works.

ICMP from Clients in the LAN2_SUBNET to the LAN1_SUBNET does not.

Is this an undocumented default setting?

If I set a Policy Route from LAN2_SUBNET to LAN1_SUBNET, ICMP work in both directions.

This seams inconsistent.

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 17  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch First Comment First Answer

    Hi @hexxit,

    Thanks for reaching out!

    To better understand the behavior you reported, I've also done a lab on my site with default configuration — using two interfaces (LAN1 and LAN2) assigned to different subnets within the same zone.

    image.png

    In my testing, ICMP traffic from the LAN1 subnet to the LAN2 subnet — and vice versa — is working as expected, with no need to add an extra policy route.

    (Results)

    image.png image.png

    For your reference, I’ve included my security policy settings as shown in the picture.

    image.png

    Since the issue you described could not be reproduced in our environment, we would like to further investigate your configuration. To better assist you, could you kindly provide us with your device configuration file?

    You may refer to the following screenshot for downloading configuration.

    (From Web GUI)

    Go to Maintenance > Firmware/File Manager > Configuration File

    image.png

    This will help us identify any potential differences or factors that might be affecting the behavior.

    Zyxel Tina

  • PeterUK
    PeterUK Posts: 3,820  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited June 12

    Odd unless you setup Policy Route from LAN2_SUBNET to LAN1_SUBNET, ICMP with SNAT outgoing interface then that might be why it works is the firewall on end device only allows ICMP within a given subnet or has no gateway