USG 110 SSL client multi VPN
Best Answers
-
The IP address space of your SSL VPN clients is 192.168.100.100-120
So if your are using policy-based IPSec site-to-site tunnel.
The VPN connection setting of local poly in HQ and remote policy need to include the IP address space of SSL VPN clients.
5 -
Hi @Ondrej
Welcome to Zyxel community.

You topology:
SSL Client(192.168.100.100)--------HQ(HQ subnet)========[VPN]======Branch(Branch Subnet)
As your scenario, SSL VPN client is able access to HQ subnet but unable access to branch subnet.
You can go to make sure if you have added routing for SSL VPN client on both of devices.
(1) On HQ device. The “branch subnet” have to add into network list of SSL VPN.

(2) Add policy route on HQ device.
Destination: Branch subnet, NextHop: VPN tunnel.

(3) Add policy route on Branch device.
a. Incoming: ZyWALL, Destination IP: SSL VPN Pool. NextHop: VPN (It is for access to Branch ZyWALL)
b. Incoming: any, Destination IP: SSL VPN Pool, NextHop: VPN (It is for access to branch subnet)

5
All Replies
-
0
Categories
- All Categories
- 164 Beta Program
- 1.7K Nebula
- 86 Nebula Ideas
- 62 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 50 Switch Ideas
- 908 WirelessLAN
- 27 WLAN Ideas
- 5.3K Consumer Product
- 172 Service & License
- 294 News and Release
- 65 Security Advisories
- 14 Education Center
- 911 FAQ
- 399 Nebula FAQ
- 249 Security FAQ
- 90 Switch FAQ
- 100 WirelessLAN FAQ
- 18 Consumer Product FAQ
- 55 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 68 About Community
- 51 Security Highlight

ping BR1,2,3.
Master Member
Zyxel Employee