ssl vpn to dynamic ipsec
Options
All Replies
-
Hi @Boris
Please help to identify where the traffic been dropped, failure test:
- Ping the SSL VPN IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Branch office.
In addition, did you set policy route and static route on both of your Zywall USG?
Zyxel Melen0 -
Hello,
1.Ping the SSL VPN IP of Zywall USG in Head office.
works
2. Ping the LAN interface IP of Zywall USG in Head office.
works
3. Ping the LAN interface IP of Zywall USG in Branch office.
no answer
Moreover, I can see in Zywall logs that packets successfully forwarded from SSL VPN to IPSec tunnel, but I cannot find it in Branch Office logs
0 -
Hi @Boris
Please help to check if you have these required configuration on both of your firewalls.
Site A:
- Create a policy route (Network > Routing > Policy Route)
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- next-hop: VPN tunnel, select the S2S tunnel to SiteB
- Security Policy (Security Policy > Policy Control)
- From: SSL_VPN
- To: IPSec_VPN
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- action: allow
- SSL VPN Network (VPN > SSL VPN > Access Privilege)
- Edit the SSL VPN policy, add 192.168.80.x(siteB) into the Network List.
Site B:
- Create a policy route (Network > Routing > Policy Route)
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- next-hop: VPN tunnel, select the S2S tunnel to SiteA
- Security Policy (Security Policy > Policy Control)
- From: LAN
- To: IPSec_VPN
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- action: allow
Zyxel Melen0 - Create a policy route (Network > Routing > Policy Route)
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight
Freshman Member
Zyxel Employee