VPN site-to-site from Nebula device to another ORG

GiuseppeR
GiuseppeR Posts: 451  Master Member
Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

Hello everyone,

I have some needs when I need to send all the traffic from a Nebula device to another ORG:

  1. I need to set a VPN from Nebula to another site (Nebula or not…).
  2. I need to set NAT Traversal in Non-Nebula VPN parameters
  3. I need to establish a full tunnel VPN

I have different devices, security routers and firewalls, but it seems to me that there are some missing options (except newest FlexH series…).

FlexH have some more pages on Nebula like this one:

immagine.png

1. Let me come back to my problem: take SCR50AXE for example.

I found this:

and this:

https://support.zyxel.eu/hc/it/articles/15366638605714-SCR50AXE-Router-sicuro-gestito-dal-cloud-Configurazione-in-Nebula-e-Guida-introduttiva#h_01HG8FKQCTA7RRXNMTXDQWFFVV

So I went here:

immagine.png

And I see this section where it seems that I can start a VPN to another site:

immagine.png

2. But here I cannot tell Nebula that VPN has to go via NAT Traversal, because I have other router in front of Nebula device.

Nebula device is in a DMZ, but to establish a VPN I have to declare that somewhere like I did when using VPN Orchestrator :

immagine.png

Is there something that I'm missing?

3. A part from FlexH:

immagine.png

it seems that I cannot route all the traffic from a Nebula device to another site VPN.

Please tell me if I did not find some Zyxel documentation regarding this request

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,703  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @GiuseppeR

    Sorry for the wait.

    1. None Nebula VPN (which is called auto-link VPN) doesn't support NAT-Traversal. So, you will need to set the port forwarding for these protocols UDP 500 & 4500 on the uplink router.
    2. The NAT-Traversal is only for Nebula VPN scenario.
    3. May I know the scope of the all traffic? All LAN's traffic? Or also device's traffic?
    Zyxel Melen


  • GiuseppeR
    GiuseppeR Posts: 451  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    Hello @Zyxel_Melen

    1. Setting the Nebula device (firewall/router) in DMZ says to the uplink router that all the incoming connections have to go to the Nebula device itself: have I to add the rule of port forwarding too? I ask this because I always set the Nebula device in DMZ (when I'm forced to use another router from ISP in front of Nebula device), usually I have all open ports on the uplink router because of the DMZ and I need only to open specific port on Nebula device (to operate with some server's services). In this scenario it seems strange to me to add a specific port forwarding rule (to the uplink router) to enable the VPN to a Nebula device.
    2. OK, so NAT Traversal is only for Nebula VPN Orchestrator.
    3. The scope to manage the full tunnel is to install a Nebula device (basic firewall or sec. router) to an employee, where the employee could attach notebook/desktop/printer forcing all the traffic inside the tunnel avoiding filters/DNS that could be used by the employee's ISP

    See you soon,

    GiuseppeR

Nebula Tips & Tricks