FLEX700H Ignoring Routing Rule




I have a static route set to push traffic to a specific IP address down an IPSEC VPN connection but the firewall seems to be ignoring it entirely. If I do a traceroute to the destination using the network tool diagnostic I just get 30 lots of ***. Other static routes using this VPN are working. Anyone have any ideas?
All Replies
-
Is this a site to site or VTI?
If site to site the FLEX H lacks routing down a tunnel VTI has more control
0 -
It's a VTI. It's baffling me as other static routes are configured in the same way and work perfectly.
Is there a log on the router to show what it is doing with the packets?
0 -
Not sure what your setup is or trying to forward
I suggest a routing rule not static route with the following:
incoming LAN
destination IP
nexthop Interface VTI
SNAT none or outgoing interface depending on the route back ideally none.It might be the case that packets are getting to there destination but the route back needs doing.
You can packet capture both ends to see what going on
0 -
Morning Peter,
We are a healthcare organisation and the IPSEC VPN is for our HSCN connectivity (secure NHS network). It's a simple configuration that everything I send down the VPN link is received by the router at the datacentre and then routed into HSCN.
I have changed from a static route to a policy route as you suggested and I can see the number of Hits increasing against the rule but the traffic still isn't routing.
The network at the far end that I am trying to get to is 10.151.128.0/22
0 -
Could you enable Zyxel support access and share the traffic flow for us to check?
Zyxel Melen0 -
I have now enabled access via Nebula for support and opened a Request #531871
0 -
So likely it is getting to 10.151.128.0/22 but if devices at the other end have a gateway the router might be going out the WAN of the source IP its replying too so you might need a routing rule that end to route traffic down the VTI of the destination back to you.
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 196 Nebula Ideas
- 123 Nebula Status and Incidents
- 6.3K Security
- 479 USG FLEX H Series
- 313 Security Ideas
- 1.6K Switch
- 82 Switch Ideas
- 1.3K Wireless
- 45 Wireless Ideas
- 6.8K Consumer Product
- 284 Service & License
- 449 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 93 Security Highlight