ssl vpn to dynamic ipsec
All Replies
-
Hi @Boris
Please help to identify where the traffic been dropped, failure test:
- Ping the SSL VPN IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Branch office.
In addition, did you set policy route and static route on both of your Zywall USG?
Zyxel Melen0 -
Hello,
1.Ping the SSL VPN IP of Zywall USG in Head office.
works
2. Ping the LAN interface IP of Zywall USG in Head office.
works
3. Ping the LAN interface IP of Zywall USG in Branch office.
no answer
Moreover, I can see in Zywall logs that packets successfully forwarded from SSL VPN to IPSec tunnel, but I cannot find it in Branch Office logs
0 -
Hi @Boris
Please help to check if you have these required configuration on both of your firewalls.
Site A:
- Create a policy route (Network > Routing > Policy Route)
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- next-hop: VPN tunnel, select the S2S tunnel to SiteB
- Security Policy (Security Policy > Policy Control)
- From: SSL_VPN
- To: IPSec_VPN
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- action: allow
- SSL VPN Network (VPN > SSL VPN > Access Privilege)
- Edit the SSL VPN policy, add 192.168.80.x(siteB) into the Network List.
Site B:
- Create a policy route (Network > Routing > Policy Route)
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- next-hop: VPN tunnel, select the S2S tunnel to SiteA
- Security Policy (Security Policy > Policy Control)
- From: LAN
- To: IPSec_VPN
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- action: allow
Zyxel Melen0 - Create a policy route (Network > Routing > Policy Route)
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 199 Nebula Ideas
- 125 Nebula Status and Incidents
- 6.3K Security
- 492 USG FLEX H Series
- 322 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 47 Wireless Ideas
- 6.8K Consumer Product
- 285 Service & License
- 455 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 95 Security Highlight
Freshman Member
Guru Member