How to set up IPSec VPN for branches to use the Internet at the head office?

Options
Zyxel_James
Zyxel_James Posts: 809 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

Question: How to set up IPSec VPN for branches to use the Internet at the head office

Scenario:

I have a USG FLEX 50H (branch) connected to a USG FLEX 200 (headquarter) via IPSec VPN. I want the branch computers to be able to access the headquarter using the headquarter's Internet.

Branch - USG FLEX 50H
LAN : 192.168.10.1

Head office - USG FLEX 200
LAN : 192.168.40.1

Answer:
This scenario could be achieved by route policy.

USG FLEX 50H needs one route policy rule

  • Incoming: interface LAN 192.168.10.1/24
  • Source Address: 192.168.10.1/24
  • Destination/Service/Source port: Any
  • Next Hop > Type: IPSec VPN Tunnel

USG FLEX 200 needs two route policy rules.

  1. Outgoing traffic for VPN remote subnet
  • Incoming: Tunnel
  • Source Address: 192.168.10.1/24
  • Destination/Service/Source port: Any
  • Next Hop > Type: Auto
  1. Return traffic from internet to VPN remote subnet
    Incoming: Any
  • Source Address: Any
  • Destination: 192.168.10.1/24
  • Service: Any
  • Next Hop: VPN tunnel