Site-to-Site VLAN Routing

Andreas_L
Andreas_L Posts: 2  Freshman Member
First Comment

Hello,
I have two Zyxel devices - a USG FLEX 50 and a SCR 50 AXE.
In between I established a site-to-site VPN.

Now I want to use a VLAN (VLAN ID 42) on the USG FLEX 50 to access internet through the SCR 50 AXE. In other words: all devices from VLAN 42 shall get the public IP address from the SCR 50, while all other VLANs still get the public IP address of the USG FLEX.

All Replies

  • Zyxel_James
    Zyxel_James Posts: 728  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    You can configure a policy routing to routing VLAN42 pass through the VPN tunnel on USG FLEX 50
    - VLAN42 needs to be enabled in Local Network in Nebula VPN.
    - Create a Policy Route, Source: VLAN42, Destintation: Any, Next-Hop: VPN tunnel

  • Andreas_L
    Andreas_L Posts: 2  Freshman Member
    First Comment

    Hello,
    Thanks for your response.
    What you suggested was my first thought as well.
    Unfortunately, when configuring a policy route I have two options for the route type - "internet traffic", "intranet traffic" and a third option "VPN traffic" which I can't use because it's light gray and not selectable.
    With "internet traffic" I can only use wan1 as next-hop, with "intranet traffic" in need to provide a well formatted IP address.
    So, I'm stuck.
    VPN is enabled for VLAN 24 (only) and VPN tunnel is up and running.

Nebula Tips & Tricks