Site to site IPSec VPN: VLAN5 <-> LAN2 interface
I’m trying to set up a tunnel between a VLAN on 1 site and a regular LAN interface on the other site. The tunnel seems to work fine, but I cannot make any connection to the devices.
I have tried site to site and vti, both seem to connect, but cannot ping. Tunnel interface between 2 LAN interfaces is no problem, but I need VLAN <-> LAN2.
VPN_TEL_LOCAL Left: Subnet: 192.168.5.0
VPN_TEL_REMOTE Left: Subnet: 192.168.10.0
VPN_TEL_LOCAL Right: Subnet: 192.168.10.0
VPN_TEL_REMOTE Right: Subnet 192.168.5.0
Still no response on both sides. Any help?
All Replies
-
You want site to site with at least one end nailed-up the status will show the tunnel is up
0 -
If you have setup the Local and remote policy right with a zone for the site to site then you might need a routing rule.
Incoming Interface
member LAN/ge
destination the remote subnet
next hop
type VPN Tunnel
tunnel your zone for the site to site
Then a firewall for LAN to zone site to site
0 -
What's about your Security Policy ? Have you allowed the traffic ?
Also,Please check there is no "Source Network Address Translation" applied.0
Categories
- All Categories
- 347 Beta Program
- 2.1K Nebula
- 114 Nebula Ideas
- 77 Nebula Status and Incidents
- 5K Security
- 44 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 65 Switch Ideas
- 901 WirelessLAN
- 33 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 326 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 831 Nebula FAQ
- 401 Security FAQ
- 219 Switch FAQ
- 190 WirelessLAN FAQ
- 45 Consumer Product FAQ
- 136 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 61 Security Highlight