USG 100 site-to -site vpn
All Replies
-
Would you like to replace VPN router-Main with ZyWALL USG100 PLUS and establish VPN between VPN route-remote and ZyWALL USG100 PLUS?
Or do you just want to insert VPN router-Main to the right-hand side of topology and keep the VPN connection between VPN router-Main and VPN route-remote?
0 -
I'd like to insert VPN main and maintain the connectio
0 -
Hi @NRdroque,
You can connect Vpn router Main to one unused lan interface (ex: lan2) of USG100-PLUS.
Disable DHCP server on lan2 and set a static IP for Vpn route Main.
On USG100-PLUS, add a static route rule as follows.
Destination IP: IP address of the subnet of Vpn route remote (ex: subnet-1 IP 192.168.30.0)
Subnet Mask: subnet mask of the subnet of Vpn router remote (ex: subnet-1 mask 255.255.255.0)
Gateway IP: lan2 IP address of USG100-PLUS (ex: 192.168.2.1)
On Vpn router Main, add a static route for traffic to company network (ex: lan1 subnet) of USG100-PLUS.
Destination IP: IP address of company network (ex: lan1 IP 192.168.1.0)
Subnet Mask: subnet mask of company network (ex: lan1 mask 255.255.255.0)
Gateway IP: the IP address of the interface which is connected to USG100-PLUS on Vpn router Main (ex: IP-1)
0 -
Hi have one question
on VPn main Router
Destination IP: IP address of company network (ex: lan1 IP 192.168.1.0)
shouldn't be the Lan2 adress?
0 -
Hi @NRdroque,
Thanks for your notification.
Here is the revised configuration.
On USG100-PLUS, add a static route rule as follows.
Destination IP: IP address of the subnet of Vpn route remote (ex: subnet-1 IP 192.168.30.0)
Subnet Mask: subnet mask of the subnet of Vpn router remote (ex: subnet-1 mask 255.255.255.0)
Gateway IP: IP-1
On Vpn router Main, add a static route for traffic to company network (ex: lan1 subnet) of USG100-PLUS.
Destination IP: IP address of company network (ex: lan1 IP 192.168.1.0)
Subnet Mask: subnet mask of company network (ex: lan1 mask 255.255.255.0)
Gateway IP: 192.168.2.1
0 -
hi,
have configure the static rule.
192.168.15.0 - the second site ip range
255.255.255.0 - the second site subnet
192.168.13.254 - ip from LAN2
i cant ping any vpn router.
it's needed to create a rule in the firewall?
0 -
i have conected as the model but i only can acess from the remote location to LAN2 ip address.
how can i comunicate with LAN1 network?
And from lan1 i can acess nothing on remote location.
thanks for all your help
0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 218 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 245 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight