How can I set up a client to site VPN with selective routing
We currently have an OpenVPN setup on our external network that allows our team to connect to the VPN and gain access to various cloud servers on our extended network. The VPN is set up to not forward all internet traffic but only traffic to selected routes within our infrastructure. This works really well but it is hosted on our external infrastructure.
We have a strong high-speed fibre connection at our HQ and we've been testing using a Zyxel USG40 as a VPN service as we have unused capacity on our connection. However - and this is where I reveal myself to being a little inexperienced - I'm struggling to find a way to limit the WAN traffic to only traffic to our cloud servers. It currently sends all traffic (LAN & WAN) through the VPN.
While it's good that the LAN traffic is correctly routed, we don't want all WAN traffic passing through our office if we can help it. Is this something possible with Zyxel devices or should I look at bringing our OpenVPN setup inside our office?
Comments
-
Hi @MIT
Welcome to Zyxel community
Add policy route can achieve the purpose.
Here is the example to add policy route
Go to Configuration > Network > Routing > Policy Route > click Add
Select the Incoming Interface, Destination Address to server and select next Hop to tunnel
After add the destination to server, add the other rule for other traffic destination is not going to server.
Don't miss this great chance to upgrade your Nebula org. for free!
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 130 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 175 USG FLEX H Series
- 256 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 235 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 81 About Community
- 69 Security Highlight