USG40 - VPN Traffic VPN2Internet/VPN2LAN and back
Hi,
I set up a IKE VPN with my USG40. The VPN establishing works well, but i don't get any internet or LAN access. In the Logs it looks like the traffic goes through VPN2any, but nothing comes back, but i doesn't see any block in the Log.
What could cause thath error?
Br
All Replies
-
Hi @IWAT,
Please send the startup-config.conf to me in private message. Thanks!
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Hi Emily
Thanks for you help, but the Startup config contains my whole network with PW.
I would prefer to send you some print screens instead.
Br Iwat0 -
Hi @IWAT,
We will need the whold startup-config.conf to check if all setting are correctly configured. Before sending the configuration file to me, you can remove this line from the configuration file.
"username admin encrypted-password xxxxxx user-type admin"
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Your WAN1 being a 192.168.x.x is no need to hide but when clients get 192.168.x.x over the VPN is not conflict with other subnets?
You may need to SNAT VPN traffic out the WAN by routeing rule unless the router upstream of USG40 does static route for the VPN clients that get 192.168.x.x
0 -
Hi Peter
The DHCP from the USG is 192.168.2.20 - 192.168.2.200. The VPN gets usually a 192.168.60.xx address, therefore it shouldn't get any conflict. To test it i changed the VPN Adress to 192.168.2.25x, but the error is the same.
Br Ivo0 -
Keep VPN clients on another subnet to not conflict
Change Local policy to 0.0.0.0
Make routing rule
incoming VPN tunnel
next hop WAN
SNAT outgoing-interfacePolicy Control
IPSec_VPN to WAN
and IPSec_VPN to LAN1note that access to a PC on LAN1 may have a firewall blocking you
0 -
I have added the Routing rule, the Policy Control has already been created.
But it is still not working.0 -
I have no idea why, but it works now…
1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight