Zywall 310 - router to router forwarding

Zywak
Zywak Posts: 8  Freshman Member
First Comment Friend Collector
edited April 2021 in Security
Hi, 

I am in a tough spot here. Bought myself a great security router that has impressive features, but lacking site-to-site IPSec VPN with SNAT.

Now, I am currently using a Zywall 310 router as my gateway. Zywall handles site-to-site VPN, including some with SNAT.

my questions, can I leave Zywall 310 in place and put my new impressive router behind it, (between Zywall and PCs).

Here's what's I'm thinking.

Zywall Wan = 172.16.2.1
Zywall LAN = 192.168.30.1

New router WAN = 192.168.30.2 (to be in same network as Zywall LAN)
New router LAN = 192.168.20.1


Now, can I setup a rule that forwards all traffic for 192.168.20.0/24 network via Zywall LAN?

Hope I can find a solution to this.

Thanks,
Richard

All Replies

  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    @Zywak
    Regarding to this case, after established ipsec vpn tunnel,
    you should add NAT rule to allow incoming traffic, and create the routing rule to force 192.168.20.0/24 go through 192.168.30.2 (New router WAN) on the your new impressive router.

Security Highlight