When creating 1:1 NAT rules for local hosts, these local hosts become unreachable through VPN IPSec.

Zyxel_Charlie
Posts: 1,034
Guru Member





The virtual server function is a "port forwarding" function.
The 1:1 NAT function is "forwarding all traffic" to the local server.
When using "1:1NAT", the traffic can't pass through to the tunnel because all traffic passes through the WAN interface.
In "packet flow explore", the priority of 1-1 SNAT is higher than site to sitesite-to-site VPN when 1:1 NAT is enabled.
To solve this problem, please reorganize the order of the routing priority.
For legacy models with ZLD 3.30 platform, use the following CLI command.
ip route control-virtual-server-rules activate
For new USG/ZyWALL series with ZLD 4.13, enable "Use Static-Dynamic Route to Control 1-1 NAT Route" on GUI.

Tagged:
0
Categories
- 7.7K All Categories
- 1.6K Nebula
- 53 Nebula Ideas
- 53 Nebula Status and Incidents
- 4.3K Security
- 215 Security Ideas
- 903 Switch
- 40 Switch Ideas
- 793 WirelessLAN
- 14 WLAN Ideas
- 5K Consumer Product
- 129 Service & License
- 260 News and Release
- 49 Security Advisories
- 6 Education Center
- 573 FAQ
- 273 Nebula FAQ
- 132 Security FAQ
- 73 Switch FAQ
- 72 WirelessLAN FAQ
- 7 Consumer Product FAQ
- Documents
- 34 Nebula Monthly Express
- 67 About Community
- 40 Security Highlight