Nebula USG FLEX 100H remote access vpn

Options
MarkoK
MarkoK Posts: 11 image  Freshman Member
First Comment

The customer has several offices that are connected with USG FLEX 100H firewalls via nebula.
we would like to make a remote access vpn, ike2 windows native client, through which we could also access other offices. this probably requires a policy route, but I haven't gotten it to work properly.
could I get instructions for this

Best Answers

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,795 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @MarkoK

    To better help you on this requirement, could you share the current VPN setting between each site?

    Are you using Nebula SD-VPN? Or?

    Zyxel Melen


  • MarkoK
    MarkoK Posts: 11 image  Freshman Member
    First Comment

    Are you using Nebula SD-VPN?

    Nebula SD-VPN used

    remote access vpn full tunnel

    side a lan 192.168.200.1

    side b lan 192.168.150.1

    remote access vpn ip pooll 10.10.12.0/24

    remote accees connect side a, and i want it can connect also side b lan

  • MarkoK
    MarkoK Posts: 11 image  Freshman Member
    First Comment

    update

    remote access connection works side a, but it canot connect side b

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,795 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @MarkoK

    You need to setup static route on side b, so side b firewall knows where should it send the packet back to remote access vpn client.

    Here is the setup steps (side a use test#1 as example, side b use test#2 as example):

    1. Navigate to Nebula side b > Menu > Monitor > firewall > VPN connection. Find the VTI IP of side a.
      image.png
    2. Navigate to Menu > Site-wide > Configure > Firewall > Routing. Add the static routing rule like below.
      image.png
    3. Connect remote access VPN and ping side b. Test result should be success. image.png

    Hope this helps.

    Zyxel Melen


  • MarkoK
    MarkoK Posts: 11 image  Freshman Member
    First Comment
    Answer ✓

    it's workin

    Thank you

  • MarkoK
    MarkoK Posts: 11 image  Freshman Member
    First Comment

    if we want to use split tunnet (ike2 or sslvpn), is that possible?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,795 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @MarkoK

    IkeV2 split tunnel, please reference this FAQ:

    Does the USG Flex H model support multiple split tunnels for the Windows native VPN client? — Zyxel Community

    SSLVPN in the latest firmware version support multiple local networks for Split Tunnel mode. You can add the remote subnet directly.

    image.png

    Additionally, the remote site must add static route.

    Zyxel Melen


  • MarkoK
    MarkoK Posts: 11 image  Freshman Member
    First Comment

    Thank you again😍

Nebula Tips & Tricks