USG 40 Pb with asymetric routing

Options
ZeroFX
ZeroFX Posts: 7
First Anniversary Friend Collector First Comment
edited April 2021 in Security

Hello,

I need to replace a Juniper Firewall and i test with a USG40.

My USG 40 is directly connected to internet.

I have 2 statics routes :

10.0.0.0/8 to 10.59.120.2

0.0.0.0 to 10.59.120.1

But i can access to internet but not in all network 10.0.0.8/24

With old Juniper it's ok, i have disable in global option sequence-number checking and SYN-flag check, and in the rule LAN to WAN i have enable sequence-number check and SYN-flag check.

Can you help me.

Thanks!





«1

All Replies

  • zyman2008
    zyman2008 Posts: 199  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @ZeroFX,

    Enable "Allow Asymmetrical Route" option in Policy Control page.

    It will bypass the TCP state check.


  • jonatan
    jonatan Posts: 146  Ally Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Use ip aliases, if the option is enabled Allow Asymmetrical Route lowers the level of security in local network - firewall does not process traffic on the areas: LAN-LAN, WAN to WAN, DMZ to DMZ, WLAN-WLAN, VPN VPN .

  • ZeroFX
    Options

    hi,

    I have never use ip alias, can you explain me it please for my case.

    Thanks you

  • jonatan
    jonatan Posts: 146  Ally Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Add the local interface of the Zyxel (10.59.120.1/24) to another virtual interface (e.g. 10.0.0.1/8) , which will serve as a gateway for your Network 2 and prescribe this gateway on the clients Neetwork2, for distribution to the Internet.

  • PeterUK
    PeterUK Posts: 2,706  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited September 2019
    Options

    To me this seems like a network overlap with 10. (but maybe its fine) I did some testing and you can get the network working if you change 10.59.120.2/24 to 192.168.120.2/24 and 10.59.120.1/24 to 192.168.120.1/24

    Switch L3 same VLAN Interface

    10.0.0.1/8

    192.168.120.2/24

    USG LAN1

    192.168.120.1/24

    USG routing

    incoming LAN1 Source 10.0.0.0/8 destination any next hop WAN SNAT outgoing-interface

    and do the static routes

    USG 10.0.0.0/8 to 192.168.120.2

    Switch L3 0.0.0.0/0 to 192.168.120.1

    All worked without needing Allow Asymmetrical Route or virtual interface...but maybe I'm missing something?

    Edit access to 10. from 192.168.120.0 so as @jonatan said you need the virtual interface on LAN1 for 10. you then need a firewall rule from LAN1 to LAN1

  • ZeroFX
    Options

    Thanks to jonatan and PeterUK, but i can't change the network IP, GW IP…

    I need just replace the Juniper FW, why it's simple with a Juniper and why a ZyXEL FW can't do this in the same IP topology?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,450  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @ZeroFX

    Welcome to Zyxel Community. ?

    Can you post the result of CLI “show ip route-settings” on USG?


    Static route:

    Router> show ip route-settings

  • ZeroFX
    Options

    Hi,

    Router> show ip route-settings

    Route          Netmask        Nexthop        Metric

    ===============================================================================

    10.0.0.0       255.0.0.0      10.59.120.2    0

    0.0.0.0        0.0.0.0        178.211.X.X      0    it's my WAN IP GW

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,450  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @ZeroFX

    There is no need to add static route 0.0.0.0/0 178.211.X.X for wan gateway.

    Please delete this routing entry and try it again.

  • ZeroFX
    Options

    Thanks Zyxel_Cooldia,

    I need enable "Allow Asymmetrical Route" ?

Security Highlight