SSL VPN from internet

Options
Residentpio
Residentpio Posts: 6 image  Freshman Member
First Comment

Hi, I have a USGFLEX100HP. I configured SSL VPN according to the manual, exported the configuration file, imported it to OpenVPN, and I can connect via VPN, but only from the local network. When I try to log in from the internet, it won't let me in. It logs in, logs in, and then stops. What do I need to do? Any NAT or routing rules? Should I disable something in the firewall?

All Replies

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    You need inbound traffic to the port for the VPN to work scan for the given port here

    GRC | ShieldsUP! — Internet Vulnerability Profiling  

  • Residentpio
    Residentpio Posts: 6 image  Freshman Member
    First Comment

    >You need inbound traffic to the port for the VPN to work scan for the given port here

    When I scan the address, I only have ports 80 and 443 open. How can I open other ports? I need this one for VPN SSL.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,669 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Residentpio

    1. Please navigate to Object > service (object) and find SSLVPN to ensure it exists and the port number is correct.
    2. Then go find "Default_Allow_WAN_to_ZyWALL" in the service group (object) and edit it.
    3. Add SSLVPN to this group and save.
    4. Please navigate to Security policy > Policy control to ensure there has a policy is "from WAN to ZyWALL with service Default_Allow_WAN_to_ZyWALL".
    Zyxel Melen


  • Residentpio
    Residentpio Posts: 6 image  Freshman Member
    First Comment

    Where can I set a rule if I want to unblock or block a port? Where can I do port forwarding? I've configured various routers and systems, and there are always firewall rules that I can manage, enable, and disable, but I don't see them in this Zyxel. The security policy contains rules that were created automatically, but I've also added them and entered "any" almost everywhere, but it doesn't help. Please help me.

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Do you have a ISP that support inbound traffic?

    Does the USGFLEX100HP have the WAN IP on its interface?

  • Residentpio
    Residentpio Posts: 6 image  Freshman Member
    First Comment

    Yes, static and public ip on wan zyxel

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited March 31

    Did you port scan the SSL port with the link I said at GRC?

    You will need a firewall rule from WAN to Zywall for that port

  • Residentpio
    Residentpio Posts: 6 image  Freshman Member
    First Comment

    I didn't do this scan. I understand I need to go to the company where I have the router and scan it from their network, because I can't scan from home and just provide the Zyxel's IP address. However, I scanned the IP address from outside with a standard scanner and it showed only 443 and 80 as open, and my SSL VPN is running on the standard port 10443. Do you think it's running on a different port if I connect from the WAN side?
    I can take screenshots of the police service; everything is standard there, but if you see this, it might become simple. It seems pretty straightforward because the VPN ports are closed on the WAN side, but I don't know how to open them and which rule is responsible for closing everything except 80 and 443. But I'm grateful for your help.

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    ok so if you scan port 10443 because its TCP from a internet scanner that lets you and shows open this would mean there is a rule allowing it. If your seeing it blocked then you need to allow just make a object with TCP 10443 and a firewall rule from WAN to Zywall for that port service.