USG FLEX 500H SSL VPN How How to set up two user groups for split and full tunnel?




Hy,
we need to create two user groups for SSL VPN (OpenVPN Client), one using split tunnel and one using full tunnel, but the GUI doesn't seem to allow it.
On the old USG firewall we could do it instead.
Do you have some tips?
Thank you.
Accepted Solution
-
Well there is a very easy way to do this but questionable as for security...
So setup with Local Networks Only (Split Tunnel) and download the config then make a copy of the config to be used for Full Tunnel open that config in notepad edit under:
verb 3
withverb 3
redirect-gatewayyou may need a routing rule
incoming any
Source Address of the VPN pool 192.168.51.0/24
next hop WANTo tighten up security you can add block rule form users who should not use the FLEX H as the gateway should anyone work out they can just add redirect-gateway to there config.
2
All Replies
-
Hi @ITC_Sercop
USG FLEX H(uOS) SSL VPN configuration is different from USG FLEX(ZLD). Could you share your scenario about why you need two different SSL VPN configuration for different users?
Zyxel Melen0 -
Yes, of course.
Some VPN users need to connect to internet servers, in addition to our lan, that check the sender's IP address so it must be our IP Company Address.
Other VPN users should use internet, while they are VPN connected, but they must use their internet connection to do so.Thanks.
0 -
Well there is a very easy way to do this but questionable as for security...
So setup with Local Networks Only (Split Tunnel) and download the config then make a copy of the config to be used for Full Tunnel open that config in notepad edit under:
verb 3
withverb 3
redirect-gatewayyou may need a routing rule
incoming any
Source Address of the VPN pool 192.168.51.0/24
next hop WANTo tighten up security you can add block rule form users who should not use the FLEX H as the gateway should anyone work out they can just add redirect-gateway to there config.
2 -
Thanks! I have helped to create the idea post.
USG FLEX H support more than one SSL VPN configuration — Zyxel Community
You may also try the method @PeterUK mentioned.
Zyxel Melen0 -
Hi,
thanks.
Your advice works perfectly. You're right, we know it's questionable as for security and we have plans to use only the "Full Tunnel" option in the near future.
0
Categories
- All Categories
- 435 Beta Program
- 2.7K Nebula
- 176 Nebula Ideas
- 118 Nebula Status and Incidents
- 6.1K Security
- 428 USG FLEX H Series
- 298 Security Ideas
- 1.6K Switch
- 79 Switch Ideas
- 1.2K Wireless
- 44 Wireless Ideas
- 6.7K Consumer Product
- 274 Service & License
- 422 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 89 Security Highlight