IPSec VPN: multiple phase 2 and SNAT

Options
fedebros
fedebros Posts: 23
First Comment Friend Collector
image  Freshman Member

Hi,

On a USG FLEX 700 H, I needed to configure an IPsec VPN with one Phase 1 and 13 Phase 2 policies.

I need to configure SNAT for all Phase 2 policies. However, when SNAT is configured in the VPN connection, it is applied only to the first Phase 2 policy and not to the others.

As a workaround, I had to configure 13 separate VPN connections using the same Phase 1 configuration, with each VPN having a different remote policy for Phase 2.

This works correctly, but wouldn't it be possible to apply SNAT to all Phase 2 policies within the same VPN connection?

Bug: Under VPN Status > IPsec VPN, in the list of connected VPNs, all connected tunnels are displayed with the Name of the first VPN that was connected, instead of their respective VPN names.

All Replies

  • Zyxel_Joshua
    Zyxel_Joshua Posts: 63
    Zyxel Certified Network Administrator - Security 5 Answers First Comment Friend Collector
    image  Zyxel Employee
    Options

    Hi @fedebros ,

    The IPSec design strategy for the USG FLEX H shifts towards the more modern route-based IPSec approach; consequently, complex configurations for policy-based designs are no longer provided. As a result, policy-based NAT is limited to the destination specified in the first Phase 2 policy. This is the design of uOS; it is not a bug.

    The following are NAT configuration guidelines for this use case by route-based IPSec,

    1. First, it is important to establish a key concept: there is no doubt that a route-based IPsec rule can establish an IPsec tunnel with a policy-based peer. The only difference lies in how the system maps to a tunnel.

    2. Therefore, you can configure a route-based IPsec rule. Just as with policy-based configurations, you can set up multiple Phase 2 entries and local/remote network policies; the VTI IP address uses default settings and does not require manual configuration.

    Note: The only limitation is that route-based rules currently require at least one route to be configured; you can specify the remote network for the first Phase 2 entry.

    3. How to setup Source NAT: (Regarding connections initiated from the LAN of this USG FLEX H to the remote end.)
    Create a policy route rule and select the VTI interface as the next-hop. For the SNAT address, select the address object to be used for translation. The system automatically routes packets into the correct tunnel based on the converted source/destination addresses.

    4. How to setup Destination NAT: (Regarding connections initiated from the remote end to the LAN side of this USG FLEX H.)

    Create a NAT virtual server rule and select the VTI interface as the incoming interface. Configure the external IP and the internal IP to which traffic is to be translated, and specify the external and internal ports.

    5. How to setup 1-1 NAT or many 1-1 NAT: (This is primarily for scenarios where both sides need to actively initiate connections to the other, or cases involving network overlap between the two ends.)

    Create a 1-1 NAT or "many 1-1 NAT" rule and select the VTI interface as the incoming interface. Configure the external IP and the internal IP to which traffic is to be translated.

    This configuration has been verified to work when connecting to a peer device, whether it is a Zyxel USG FLEX/ATP firewall or a third-party firewall (e.g., Fortinet fortigate).