Issue with VPN Connecting to Internal Devices from WAN Failover to LAN1
Options
All Replies
-
I think you are misunderstanding my issue. The client connects just fine and has no issues. I am not able to access resources on the internal lan once the authentication / connection is established. The logs show connection is fine the traffic is being blocked hence what my first post stated.PeterUK said:So that will be L2TP over IPSec? Can you check the setting in the made VPN for windows has “use default gateway on remote network” checked.
Control Panel\Network and Internet\Network Connections
0 -
Yes client can connect fine but if the option is not checked then it will not work.
Also check a zone is set for the VPN on zywall
0 -
For the above to do with a VPN problem the Source IP would have to be set for the VPN subnet normally a VPN subnet you set for the connecting client would be 192.168.x.xdcgtechnologies said:The error in logs is below:
Match default rule, DNAT Packet, DROP [count=2] - 166.x.x.x 192.x.x.x - Access Block0 -
Another thing is if you enable for routing"Use IPv4 Policy Route to Overwrite Direct Route"0
-
What are the parameters for the zone that needs to be set? Thank you.PeterUK said:Yes client can connect fine but if the option is not checked then it will not work.
Also check a zone is set for the VPN on zywall
0 -
Yes that is correct as I am pulling a different ip address on the 192.168.7.x as an example. Thank you.PeterUK said:
For the above to do with a VPN problem the Source IP would have to be set for the VPN subnet normally a VPN subnet you set for the connecting client would be 192.168.x.xdcgtechnologies said:The error in logs is below:
Match default rule, DNAT Packet, DROP [count=2] - 166.x.x.x 192.x.x.x - Access Block0 -
So I fixed it. It turns out under "VPN Connection". The checkbox next to "Use Policy Route to control dynamic IPSec rules" was checked. I unchecked it and everything started working as usual. That was causing all the traffic to be blocked. Thank you for help and sorry for the confusion.0
-
It be set in the VPN setting for Phase 2dcgtechnologies said:What are the parameters for the zone that needs to be set? Thank you.
0
Categories
- All Categories
- 440 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 528 USG FLEX H Series
- 331 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 50 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.6K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Ally Member
Guru Member