Why I can't access VPN peer gateway Web GUI by remote interface IP?

Options
Zyxel_James
Zyxel_James Posts: 809 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

Scenario:
I have two USG FLEX H Firewalls configured Site-to-Site tunnel between them. However, I found out I can't access the local Web GUI through the tunnel from the remote side.

Question:
Why I can't access VPN peer gateway Web GUI by remote interface IP even when a Policy Route is configured?

Answer:
Local out traffic from the firewall itself won't go into the tunnel. And Policy Route can't control the local out traffic of the firewall itself, while Static Route can.
So you need Statis Route to direct the return local traffic to the VPN tunnel.