Multiple VPN Tunnels Site2Site (working) but no connection to PC's

Options
wemida
wemida Posts: 4 image  Freshman Member
First Comment Friend Collector

I have established 3 Sites with direct Site2Site VPN Tunnels. They work but it's not (only partially) possible to connect to specific PC's via Remote Desktop (RDP) nor ping them.Some of the connections work though.. Here is the situation:

Site 1: Uses WAN from a Bridged Modem and has the public fixed IP, Site 2 and 3 are in the DMZ behind the modem (XMG3927) routet to the fixed IP of the zywall also using a public ip.

Site 1: LAN: 192.168.36.0/24 – WAN: public IP

Site 2: IP: 192.168.45.0/24 – WAN: 192.168.123.1 plus puplic ip as 2nd

Site 3: IP: 192.168.35.0/24 – WAN: 192.168.1.100 plus public ip as 2nd

All have 2 policy based manual link VPN configured

1 → 2: 192.168.36.0/24 ←→ 192.168.45.0/24

1 → 3: 192.168.36.0/24 ←→ 192.168.35.0/24

2 → 1: 192.168.45.0/24 ←→ 192.168.36.0/24

2 → 3: 192.168.45.0/24 ←→ 192.168.35.0/24

3 → 1: 192.168.35.0/24 ←→ 192.168.36.0/24

3 → 2: 192.168.35.0/24 ←→ 192.168.45.0/24

connection checks (ping):

2 -> 3 = fail

2 -> 1 = fail

3 -> 2 = pass

3 -> 1 = fail

1 -> 2 = pass

1 -> ACC = fail

Do i need to add any routing or something that i'm missing?

All Replies

  • PeterUK
    PeterUK Posts: 4,247 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited November 1

    But has RDP or ping worked before by other setup? could be the PC's firewall?

    Do you have any other routing rules in place on the sites?

    If from site 2 192.168.45.0/24 on the remote sites 1 and 3 you do a packet capture by USG to the given LAN's for port 3389 are the TCP SYN getting to the clients with a SYN ack back?

  • wemida
    wemida Posts: 4 image  Freshman Member
    First Comment Friend Collector
  • PeterUK
    PeterUK Posts: 4,247 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    As we know 3 to 2 and 1 to 2 work disable the VPN tunnels and try them one at a time.

  • wemida
    wemida Posts: 4 image  Freshman Member
    First Comment Friend Collector

    I tried everything and its still the same picture it works one way but not the other way around. Studerus (Zyxel switzerland tried also 3 hours!!) i need support now! it seems to be a software issue as such setups worked perfectly with the old firewalls.

  • PeterUK
    PeterUK Posts: 4,247 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited November 19

    If your trying to get it all working in one go this may cause problem in finding the cause.

    So start with one tunnel enabled and work from there.

    Do you have routing rules setup for any thing?

    did all sites got a new USG or just site 1?

  • amateur_netops
    amateur_netops Posts: 13 image  Freshman Member
    First Comment First Anniversary

    Set MTU to 1300 - no idea why that worked before in my case - but I had the same problem and that's what worked for me