VPN tunnel established but no traffic - Zywall USG 50 to Palo Alto

Options
I've setup an IPSec VPN gateway and connection from my USG 50 to a Palo Alto 3220 firewall.   My USG 50 is connected to my home internet router so my WAN IP is a non-routable address assigned via DHCP (10.0.0.244). The tunnel comes up fine and stays connected but I can't reach the networks on the other side of the Palo.  I tried to setup both a Policy Route and a Static Route but traffic still will not reach the other side.  When I try run a traceroute to one of the remote networks directly from the CLI of the USG 50 it goes to my internet gateway at 10.0.0.1 instead of over the tunnel.  It looks like my firewall rules are fine as all traffic is permitted from LAN to any destination, and all traffic is allow from IPSec_VPN to any destination except ZyWALL.  Any suggestions?  

All Replies

  • jasailafan
    jasailafan Posts: 191  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    To clarify the issue is on firewall or routing, try to disable firewall on both USG 50 and Palo Alto 3220, then check the traffic again. As I know, you don't need to add any policy route on USG 50 for site to site vpn.

Security Highlight