How can remote access VPN (full tunnel) reach remote sites by site-to-site VPN?

Options
Zyxel_Melen
Zyxel_Melen Posts: 4,835 image  Zyxel Employee
Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
edited May 14 in VPN

Assume the remote access VPN connects to site a. To reach the requirement, we need to setup static route on side b, so side b firewall knows where it should send the packet back to remote access VPN client.

Here are the setup steps for full tunnel mode (side a use test#1 as example, side b use test#2 as example):

  1. Navigate to Nebula side b > Menu > Monitor > firewall > VPN connection. Find the VTI IP of side a.
    image.png
  2. Navigate to Menu > Site-wide > Configure > Firewall > Routing. Add the static routing rule like below.
    image.png
  3. Connect remote access VPN and ping side b. Test result should be success. image.png
Zyxel Melen