When creating 1:1 NAT rules for local hosts, these local hosts become unreachable through VPN IPSec.

Zyxel_Charlie
Posts: 1,034
Zyxel Employee





The virtual server function is a "port forwarding" function.
The 1:1 NAT function is "forwarding all traffic" to the local server.
When using "1:1NAT", the traffic can't pass through to the tunnel because all traffic passes through the WAN interface.
In "packet flow explore", the priority of 1-1 SNAT is higher than site to sitesite-to-site VPN when 1:1 NAT is enabled.
To solve this problem, please reorganize the order of the routing priority.
For legacy models with ZLD 3.30 platform, use the following CLI command.
ip route control-virtual-server-rules activate
For new USG/ZyWALL series with ZLD 4.13, enable "Use Static-Dynamic Route to Control 1-1 NAT Route" on GUI.

Tagged:
0
Categories
- 8.5K All Categories
- 1.6K Nebula
- 71 Nebula Ideas
- 57 Nebula Status and Incidents
- 4.5K Security
- 227 Security Ideas
- 982 Switch
- 46 Switch Ideas
- 879 WirelessLAN
- 24 WLAN Ideas
- 5.1K Consumer Product
- 158 Service & License
- 280 News and Release
- 61 Security Advisories
- 13 Education Center
- 581 FAQ
- 263 Nebula FAQ
- 160 Security FAQ
- 76 Switch FAQ
- 75 WirelessLAN FAQ
- 7 Consumer Product FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 62 About Community
- 46 Security Highlight