[USG Flex H] - Unable to see network devices Remote Access VPN (full tunnel)

Options
Maverick87
Maverick87 image  Master Member
Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
edited August 12 in USG FLEX H Series

Hello,
I've configured a Remote Access VPN in full tunnel settings, but in this way I'm not able to see services into local network devices.
The subnet configured is 192.168.168.0/24, instead the DomoNET is 192.168.0.1 (192.168.0.0/24).

For example: I use Home Assistant that use 8123 port.
I've configured the policy route in this way:
- From: IPSec_VPN
- To: DomoNET_VLAN
- Source: Any
- Destination: DomoNET
- Service: Home Assistant object (port 8123)

This rule receive hints, but seems that is missing the "return" policy; it's as if a route or something is missing; the request arrives from IPSec to DomoNET, but it's as if the DomoNET doesn't know where to send the packet.
There are no errors in the logs.

I've tried also a configure some SNAT:
- Incoming: DomoNET_VLAN
- Source: DomoNET
- Destination: IPSEC_Subnet
- Service: Any
- DSCP Code: Any
- DSCP Mark: Preserve
- Next Hop: Auto
- SNAT: None

And:

- Incoming: Any
- Source: IPSEC_Subnet
- Destination: DomoNET
- Service: Any
- DSCP Code: Any
- DSCP Mark: Preserve
- Next Hop: Auto
- SNAT: outgoing-interface

But nothing works.

Can you help me on this?

Thank you

Accepted Solution

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Answer ✓
    Options

    I can't believe it MY FAULT!

    The raspberry (DomoNET) have the internal wifi that have configured the subnet 192.168.168.0/24, so it is therefore in conflict.

    Changing the IPSec subnet, to another subnet never used, all works like a sharm without any other routes.

    Thank you @PeterUK

All Replies