VPN IPSEC with a nat-enabled router
Hi. I've a litte question about a VPN problem.
The situation is this:
Internet =70.4.... (with 1 public static IP) => Fiber routrer == 192.168.1.x ==> USG110 ==192.168.10.x= => LAN
The customer has another person that needs to connect to the lan. I tried with SSL VPN and it worked fine (I natted all ports from router to firewall), but my boss sold them the IPSEC license. I tried the autoconfiguration but, when I download the cofiguration from the client, it sets the destination IP the wan IP of the firewall (192.168.1.2) and not the external one. So the client won't work. If I manually the remote gateway on the client with the public IP, everything stops after "sending phase 1 ID".
Unfortunatly I cannot put the pubblic IP on firewall's wan
I read some docs, but I cannot find my actual situation to search any hint for the config
0
All Replies
-
Hi @Cava
In your scenario, the VPN must be established via the public ip address, so the following configuration must be done on the fiber router:
- Static NAT:
Source: Public IP address on the fiber router
Destination: 192.168.1X (WAN USG110)
Port: 500 UDP, 4500 UDP
And the IP protocols: ESP (Ip protocol 50) and AH (ip protocol 51).
Best regards
0 -
Thanks. There was a rule for a video conference sw that was natting the 4500 on another network.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight