Zyxel USG Flex H series - How to configure route from VPN client (Site A vpn server) to Site B

MitjaS3NEXT
MitjaS3NEXT Posts: 7  Freshman Member
First Comment Friend Collector First Anniversary

Hey dear community,
can't figure out how to configure this scenario

Site A - Zyxel USG 100H series (configured Remote Access VPN for client, configured Site to Site VPN from site A to site B)
Site B - Zyxel USG 100 series (configured Site to Site VPN from site B to site A)

Site to site VPN works perfectly in both ways. (Site A <> Site B)
Remote Access VPN - works perfectly, clients can cannot form other locations and acces devices on LAN of Site A.

How to configure route on the Site A zyxel usg flex H series (and probably also what to configure on Site B) that VPN clients can access devices on LAN of Site B?

All Replies

  • PeterUK
    PeterUK Posts: 3,573  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited January 31

    Currently the FLEX H does not have next hop VPN tunnel but VTI for Route-based does if you set that up as site to site instead of Policy-based.

    however one thing you can try which I'm not sure will work is to add the the VPN site to site you have in Phase 2 is your local IP pool for Remote Access VPN to remote subnet on the FLEX H

    On USG 100 you will need to add a routing rule incoming LAN Destination Remote Access VPN next hop VPN tunnel.

  • MitjaS3NEXT
    MitjaS3NEXT Posts: 7  Freshman Member
    First Comment Friend Collector First Anniversary
  • PeterUK
    PeterUK Posts: 3,573  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Yes guess you have to setup VTI

  • MitjaS3NEXT
    MitjaS3NEXT Posts: 7  Freshman Member
    First Comment Friend Collector First Anniversary
    edited January 31

    Not an option :( since there also has to work a "site A to site C VPN tunel" where a 3rd party company requires policy-based VPN site to site.
    What fascinates me the most is that the H series is the latest USG FLEX Zyxel series, how can the ‘NEXT HOP VPN TUNNEL’ setting be missing?

  • PeterUK
    PeterUK Posts: 3,573  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    The FLEX H is on going to add stuff from older models