Zyxel USG 50/100/110 vpn phase 2 order
Hello! Forgive me my bad english
Need some help. Is there any possibility to change order of automatic ipsec vpn routes?
There is Zyxel USG 50/100/110 (i got few of them) that connected to many networks using ipsec. I got one ipsec tunnel to pfsense router for internet access, so remote network in phase 2 points to 0.0.0.0/0
Then i make another tunnel to another device with remote policy, e.g. 192.168.111.0/24, and i cannot access this network. I looked at the "packet flow explore" tab and see that 0.0.0.0/0 route stands above 192.168.111.0/24 route, so its obvious why i cannot connect to 192.168.111.0/24 hosts. I see that site-to-site vpn routes lists in the same order as phase 2 configurations. So it comes to me, if i can change its order i can make it all work
I know i can make policy route leads to 192.168.111.0/24 through corresponding tunnel, but maybe there's some other way to make it work?
Thanks
Need some help. Is there any possibility to change order of automatic ipsec vpn routes?
There is Zyxel USG 50/100/110 (i got few of them) that connected to many networks using ipsec. I got one ipsec tunnel to pfsense router for internet access, so remote network in phase 2 points to 0.0.0.0/0
Then i make another tunnel to another device with remote policy, e.g. 192.168.111.0/24, and i cannot access this network. I looked at the "packet flow explore" tab and see that 0.0.0.0/0 route stands above 192.168.111.0/24 route, so its obvious why i cannot connect to 192.168.111.0/24 hosts. I see that site-to-site vpn routes lists in the same order as phase 2 configurations. So it comes to me, if i can change its order i can make it all work
I know i can make policy route leads to 192.168.111.0/24 through corresponding tunnel, but maybe there's some other way to make it work?
Thanks
0
Comments
-
Hi @arukashi,
Welcome to Zyxel community. Can you post your network topology with IP subnet.
It would be helpful and easier to know the scenario.
0 -
Hello!
okay. Issue concerns Zyxel USG 100/110 with lan 192.168.23.0/24
Tunnel1 is used for routing internet traffic to pfsense, other tunnels used for accessing other bogon networks (192.168.20.0-22.0/24).
So, when all of this tunnels connected, automating routing rules generated, right? And this rules lists in the same order as we see in VPN -> IPSec VPN -> Connections. If tunnel1 rule is the first one, all traffic flows to pfsense, and traffic for tunnel 20/21/22 never gets to its right way. If tunnel1 rule is the last, its all okay.
If i create another ipsec tunnel it becomes last, and traffic for never reach target network. Is there any way i can change this order of rules without recreating tunnel1 rule?
Thanx
0 -
Hi @arukashi,
It is unable to change the order of the IP Sec VPN tunnels in packet flow when the tunnel had been created, but you can control routing to corresponding tunnels by policy route,
Because the traffic goes to policy route first, then Site to Site VPN.
0 -
Zyxel_Cooldia said:Hi @arukashi,
It is unable to change the order of the IP Sec VPN tunnels in packet flow when the tunnel had been created, but you can control routing to corresponding tunnels by policy route,
Because the traffic goes to policy route first, then Site to Site VPN.
Is it possible to make zyxel usg not to create automatic routing rules for vpn networks? Since i dont need them and i will make my own rules anyway
0 -
0
-
All right, thanks a lot
Maybe it will be useful to be able to change ipsec rule order, i hope would correct this in latest firmwares
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight