ssl vpn to dynamic ipsec
All Replies
-
Hi @Boris
Please help to identify where the traffic been dropped, failure test:
- Ping the SSL VPN IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Head office.
- Ping the LAN interface IP of Zywall USG in Branch office.
In addition, did you set policy route and static route on both of your Zywall USG?
Zyxel Melen0 -
Hello,
1.Ping the SSL VPN IP of Zywall USG in Head office.
works
2. Ping the LAN interface IP of Zywall USG in Head office.
works
3. Ping the LAN interface IP of Zywall USG in Branch office.
no answer
Moreover, I can see in Zywall logs that packets successfully forwarded from SSL VPN to IPSec tunnel, but I cannot find it in Branch Office logs
0 -
Hi @Boris
Please help to check if you have these required configuration on both of your firewalls.
Site A:
- Create a policy route (Network > Routing > Policy Route)
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- next-hop: VPN tunnel, select the S2S tunnel to SiteB
- Security Policy (Security Policy > Policy Control)
- From: SSL_VPN
- To: IPSec_VPN
- source: SSL VPN subnet
- destination: 192.168.80.x(SiteB)
- action: allow
- SSL VPN Network (VPN > SSL VPN > Access Privilege)
- Edit the SSL VPN policy, add 192.168.80.x(siteB) into the Network List.
Site B:
- Create a policy route (Network > Routing > Policy Route)
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- next-hop: VPN tunnel, select the S2S tunnel to SiteA
- Security Policy (Security Policy > Policy Control)
- From: LAN
- To: IPSec_VPN
- source: 192.168.80.x(SiteB)
- destination: SSL VPN subnet
- action: allow
Zyxel Melen0 - Create a policy route (Network > Routing > Policy Route)
Categories
- All Categories
- 438 Beta Program
- 2.7K Nebula
- 188 Nebula Ideas
- 121 Nebula Status and Incidents
- 6.2K Security
- 454 USG FLEX H Series
- 303 Security Ideas
- 1.6K Switch
- 81 Switch Ideas
- 1.3K Wireless
- 44 Wireless Ideas
- 6.8K Consumer Product
- 278 Service & License
- 435 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 91 Security Highlight