VPN Policy Route on NSG 100

Elgen07
Elgen07 Posts: 6
First Comment Second Anniversary
edited July 2022 in Security


Hi


I am testing VPN connections between USG FLEX 100 and NSG 100 since USG FLEX is the new version of NSG.
My problem is that I cannot select VPN when I want to create a Policy Route on NSG, VPN is greyed out. What do I do to be able to create a Policy Route for traffic that will use the VPN connection?

Regards
Olav



All Replies

  • Elgen07
    Elgen07 Posts: 6
    First Comment Second Anniversary
    No, I have not solved the problem, but I saw that the NSG series is End of Life, so I wonder if there will be a solution to this problem

    End of life | Zyxel

    h
    Olav
  • Zyxel_Melen
    Zyxel_Melen Posts: 2,409  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Hi @Elgen07,

    When creating Nebula VPN tunnel between NSG and USG FLEX, you could not select VPN option when creating a Policy Route on NSG or USG FLEX.
    This is a limitation on Nebula.
    In order to select VPN in policy route, I suggest you create a Non-Nebula VPN on the site-to-site VPN setting page.
    Here is the configuration example:

    After saving the configuration, you will be able to select VPN when creating a Policy Route on NSG or USG FLEX.


    In addition, if you want to create a policy route from NSG LAN to USG FLEX LAN, you only need to select "use VPN" for those LANs on the site-to-site VPN setting page. You don't need to manually create a policy route since Nebula will generate the policy after you select the option.

  • Elgen07
    Elgen07 Posts: 6
    First Comment Second Anniversary
    Hi
      Thanks for the reply, I've tested and I get the traffic through although it's not as good functionality as Nebula VPN

    h
    Olav

Security Highlight