USG 40 Pb with asymetric routing

ZeroFX
ZeroFX Posts: 7  Freshman Member
First Comment Friend Collector Second Anniversary
edited April 2021 in Security

Hello,

I need to replace a Juniper Firewall and i test with a USG40.

My USG 40 is directly connected to internet.

I have 2 statics routes :

10.0.0.0/8 to 10.59.120.2

0.0.0.0 to 10.59.120.1

But i can access to internet but not in all network 10.0.0.8/24

With old Juniper it's ok, i have disable in global option sequence-number checking and SYN-flag check, and in the rule LAN to WAN i have enable sequence-number check and SYN-flag check.

Can you help me.

Thanks!





«1

All Replies

  • zyman2008
    zyman2008 Posts: 219  Master Member
    25 Answers First Comment Friend Collector Seventh Anniversary

    Hi @ZeroFX,

    Enable "Allow Asymmetrical Route" option in Policy Control page.

    It will bypass the TCP state check.


  • jonatan
    jonatan Posts: 184  Master Member
    5 Answers First Comment Friend Collector Seventh Anniversary

    Use ip aliases, if the option is enabled Allow Asymmetrical Route lowers the level of security in local network - firewall does not process traffic on the areas: LAN-LAN, WAN to WAN, DMZ to DMZ, WLAN-WLAN, VPN VPN .

  • ZeroFX
    ZeroFX Posts: 7  Freshman Member
    First Comment Friend Collector Second Anniversary

    hi,

    I have never use ip alias, can you explain me it please for my case.

    Thanks you

  • jonatan
    jonatan Posts: 184  Master Member
    5 Answers First Comment Friend Collector Seventh Anniversary

    Add the local interface of the Zyxel (10.59.120.1/24) to another virtual interface (e.g. 10.0.0.1/8) , which will serve as a gateway for your Network 2 and prescribe this gateway on the clients Neetwork2, for distribution to the Internet.

  • PeterUK
    PeterUK Posts: 3,331  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited September 2019

    To me this seems like a network overlap with 10. (but maybe its fine) I did some testing and you can get the network working if you change 10.59.120.2/24 to 192.168.120.2/24 and 10.59.120.1/24 to 192.168.120.1/24

    Switch L3 same VLAN Interface

    10.0.0.1/8

    192.168.120.2/24

    USG LAN1

    192.168.120.1/24

    USG routing

    incoming LAN1 Source 10.0.0.0/8 destination any next hop WAN SNAT outgoing-interface

    and do the static routes

    USG 10.0.0.0/8 to 192.168.120.2

    Switch L3 0.0.0.0/0 to 192.168.120.1

    All worked without needing Allow Asymmetrical Route or virtual interface...but maybe I'm missing something?

    Edit access to 10. from 192.168.120.0 so as @jonatan said you need the virtual interface on LAN1 for 10. you then need a firewall rule from LAN1 to LAN1

  • ZeroFX
    ZeroFX Posts: 7  Freshman Member
    First Comment Friend Collector Second Anniversary

    Thanks to jonatan and PeterUK, but i can't change the network IP, GW IP…

    I need just replace the Juniper FW, why it's simple with a Juniper and why a ZyXEL FW can't do this in the same IP topology?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @ZeroFX

    Welcome to Zyxel Community. ?

    Can you post the result of CLI “show ip route-settings” on USG?


    Static route:

    Router> show ip route-settings

  • ZeroFX
    ZeroFX Posts: 7  Freshman Member
    First Comment Friend Collector Second Anniversary

    Hi,

    Router> show ip route-settings

    Route          Netmask        Nexthop        Metric

    ===============================================================================

    10.0.0.0       255.0.0.0      10.59.120.2    0

    0.0.0.0        0.0.0.0        178.211.X.X      0    it's my WAN IP GW

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @ZeroFX

    There is no need to add static route 0.0.0.0/0 178.211.X.X for wan gateway.

    Please delete this routing entry and try it again.

  • ZeroFX
    ZeroFX Posts: 7  Freshman Member
    First Comment Friend Collector Second Anniversary

    Thanks Zyxel_Cooldia,

    I need enable "Allow Asymmetrical Route" ?

Security Highlight