IPSec VPN Site to Site

IPO
IPO Posts: 4  Freshman Member
First Comment Fifth Anniversary
edited April 2021 in Security
Hello,

I'm trying to connect 2 sites through Zywall 110 (VPN site-to-site), but I don't understand why they dont work.

VPN connection are both connected.
I setup route for VPN connection.

In local site, when I try to connect to remote Zywall, I can't see anything in the remote Zywall log.
In remote site, when I try to connect to local Zywall, I can see connection on local Zywall log, but cant connect to it.


I have the impression that the local site does not allow to go out to the VPN, although a route has been created.

Do you have any idea of my misconfiguration ? 

Thanks,
Geoffrey.

All Replies

  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary

    @IPO
    Regarding to this case,
    if the topology is SiteA----VPN-----SitB, on Site A, you need to create the policy routing Source: any, Destination: SiteB's local subnet, next Hop: tunnel, VPN profile. On siteB, vice versa.

    After complete the setting, and established VPN connection, you can enter remote local IP to access Peer device.
    Charlie

  • IPO
    IPO Posts: 4  Freshman Member
    First Comment Fifth Anniversary
    Hi,

    Thanks for your answer.

    This route is already created : 



    IPO-IN-ZOLA is the SiteB subnet, 192.168.6.0/24
    SiteA subnet is 172.16.0.0/16

    I tried to configure route like that : 

    But not working too.

    The firmware is up to date, v4.33(AAAA.0) on the 2 sites. 
  • RaphaelOIiveria
    RaphaelOIiveria Posts: 35  Freshman Member
    First Answer First Comment Friend Collector First Anniversary
    HI, IPO.

    When you access the USG, in security policy/Policy Control exist many rules that are default.
    See if exist a rule that allow the traffic from TUNNEL to Zywall.
  • IPO
    IPO Posts: 4  Freshman Member
    First Comment Fifth Anniversary
    Hi,

    The default rules allow connection.
    When I disabled policy control, they does'nt work too.

    For information, i've already a VPN site-to-site which is working between SiteB to SiteC, I done the same rules and parameters, without success...
  • IPO
    IPO Posts: 4  Freshman Member
    First Comment Fifth Anniversary
    Re,

    I found the problem, it's my DNS server !

    When I dont use my local DNS server, it's working fine !
    Now I have to find why...

    Anyway, no problem with my Zywall, so I can close this topic.

    Thanks for your help !