VPN access other interface
Hi guys,
is there a way to gain access to another interface through VPN (Site to Site)?
Let's say the tunnel gains access to LAN1 on both sides, now on side a i have a printer in LAN2 and on side b i have a printer in LAN3.
What i need is to access LAN2 on side b and LAN3 on side a.
Thank you.
Comments
-
What's the firewall model on both side ?
Zyxel firewall with ZLD 4.20 or above can support both policy-based and route-based IPSec VPN.
1.For policy-based IPSec (all ZLD version)
(1)on side a, add a policy route src.: side a LAN2 subnet to dst.: side b LAN3 subnet, next-hop: the IPSec tunnel to side b
(2)on side b, add a policy route src.: side b LAN3 subnet to dst.: side a LAN2 subnet, next-hop: the IPSec tunnel to side a
2.For route-based IPSec (ZLD 4.20 or above)
(1)on side a, add a static route, dst.: side b LAN3 subnet, the vti interface to side b
(2)on side b, add a static route, dst.: side a LAN2 subnet, the vti interface to side a
0 -
Hi,
Side A, ATP500, FW 4.35
Side B, USG 50, FW 3.30(BDS.9)
I'll try and i'll let you know.
Very much appreciated!
0 -
I went with the static route but i still don't get no response to my pings, on both sides.
0 -
Just to be more precise, with the static route i get the following answer from each sides Zywall:
Reply from "IP Zywall": destination host unreachable
0 -
You have the old USG50 that only support policy-based IPSec.
So that you need to use policy route on both side.
Static route is not work on your case.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.7K Security
- 281 USG FLEX H Series
- 278 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 251 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight