VPN with router

federicofederigi
federicofederigi Posts: 5  Freshman Member
First Comment First Anniversary
edited April 2023 in Security

i'm trying with usg40

wan 192.168.8.2 lan 192.168.9.1 Public ip of router 2.42.21.. .. router 192.168.8.1

if connect my linux pc on 192.168.8.?? VPN ike2 on 192.168.8.2 con preshared-key work regularly.

if i connect the same vpn but on 2.42.21. . .. after NAT of ports 500 e 4500 udp on router

connect temporarly and don't work

All Replies

  • federicofederigi
    federicofederigi Posts: 5  Freshman Member
    First Comment First Anniversary

    other vpn with same USG same router but other client VPN on windows work OK

  • Fred_77
    Fred_77 Posts: 120  Ally Member
    5 Answers First Comment Friend Collector Fourth Anniversary

    Hi (ciao) @federicofederigi

    afaik also ports 50 an 51 should be natted from your vodafone station to usg.

    P.S. suppongo tu abbia buone ragioni per non dirottare tutto il traffico all'usg e gestire le policy di sicurezza su quest'ultimo…

    Fred

  • federicofederigi
    federicofederigi Posts: 5  Freshman Member
    First Comment First Anniversary

    Ho girato tcp 50 e tcp 51. Ho girato tutte le porte sul USG40 e messo in dmz e disabilitato policy.

    ma fa la stessa cosa, sembra connesso ma non funziona, e dopo qualche minuto si scollega

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,396  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @federicofederigi,
    If the USG40 is placed behind the router, you need to create both NAT and firewall rules to allow UDP port 500 and 4500 on that router. On USG40, set 0.0.0.0/0 in the Local Policy of VPN Connection.

  • federicofederigi
    federicofederigi Posts: 5  Freshman Member
    First Comment First Anniversary

    do you mean this local policy? (named LINUX_ALL)

    with this i have the same problem

  • federicofederigi
    federicofederigi Posts: 5  Freshman Member
    First Comment First Anniversary

    this is new log. . . i think another step. . . but connection lose immediately . .

Security Highlight