USG 40 Pb with asymetric routing
Hello,
I need to replace a Juniper Firewall and i test with a USG40.
My USG 40 is directly connected to internet.
I have 2 statics routes :
10.0.0.0/8 to 10.59.120.2
0.0.0.0 to 10.59.120.1
But i can access to internet but not in all network 10.0.0.8/24
With old Juniper it's ok, i have disable in global option sequence-number checking and SYN-flag check, and in the rule LAN to WAN i have enable sequence-number check and SYN-flag check.
Can you help me.
Thanks!
All Replies
-
Hi @ZeroFX,
Enable "Allow Asymmetrical Route" option in Policy Control page.
It will bypass the TCP state check.
1 -
Use ip aliases, if the option is enabled Allow Asymmetrical Route lowers the level of security in local network - firewall does not process traffic on the areas: LAN-LAN, WAN to WAN, DMZ to DMZ, WLAN-WLAN, VPN VPN .
1 -
hi,
I have never use ip alias, can you explain me it please for my case.
Thanks you
0 -
Add the local interface of the Zyxel (10.59.120.1/24) to another virtual interface (e.g. 10.0.0.1/8) , which will serve as a gateway for your Network 2 and prescribe this gateway on the clients Neetwork2, for distribution to the Internet.
1 -
To me this seems like a network overlap with 10. (but maybe its fine) I did some testing and you can get the network working if you change 10.59.120.2/24 to 192.168.120.2/24 and 10.59.120.1/24 to 192.168.120.1/24
Switch L3 same VLAN Interface
10.0.0.1/8
192.168.120.2/24
USG LAN1
192.168.120.1/24
USG routing
incoming LAN1 Source 10.0.0.0/8 destination any next hop WAN SNAT outgoing-interface
and do the static routes
USG 10.0.0.0/8 to 192.168.120.2
Switch L3 0.0.0.0/0 to 192.168.120.1
All worked without needing Allow Asymmetrical Route or virtual interface...but maybe I'm missing something?
Edit access to 10. from 192.168.120.0 so as @jonatan said you need the virtual interface on LAN1 for 10. you then need a firewall rule from LAN1 to LAN1
1 -
Thanks to jonatan and PeterUK, but i can't change the network IP, GW IP…
I need just replace the Juniper FW, why it's simple with a Juniper and why a ZyXEL FW can't do this in the same IP topology?
0 -
Hi @ZeroFX
Welcome to Zyxel Community. ?
Can you post the result of CLI “show ip route-settings” on USG?
Static route:
Router> show ip route-settings
0 -
Hi,
Router> show ip route-settings
Route Netmask Nexthop Metric
===============================================================================
10.0.0.0 255.0.0.0 10.59.120.2 0
0.0.0.0 0.0.0.0 178.211.X.X 0 it's my WAN IP GW
0 -
Hi @ZeroFX
There is no need to add static route 0.0.0.0/0 178.211.X.X for wan gateway.
Please delete this routing entry and try it again.
0 -
Thanks Zyxel_Cooldia,
I need enable "Allow Asymmetrical Route" ?
0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 218 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 245 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight