problems in configuration usg20w without wan interface

Options
alexey
alexey Posts: 188  Master Member
First Anniversary 10 Comments Friend Collector
edited April 2021 in Security

Hello. In 1 site we setup usg20w-vpn with l2 vpn from provider.

I builded ipsec vpn & vti interface.

Localnet 172.20.0.0/20 in central site & 172.20.52.0/24 usg20w-vpn (172.20.52.1 ip of Zywall).

VTI 172.24.0.5/30 central & 172.24.0.6/30 usg20w-vpn.

VPN provider connect to p3 in Lan1 zone, local connect to p4 Lan2 zone.

From central site i can ping all network below ZW and vice versa, exception internal ZW ip addresses 172.20.52.1 & 172.24.0.6. I can access to ZW only via provider vpn ip on p3.

I added policy routes to ZW to 172.20.0.0/20 via vti interface.

ZW can't ping 172.20.0.0/20 range. What i must change to have access to ZW by internal ip addresses & ZW start see remote lan?

Via cli ZW gives message, that Network is unreachable, than i try ping 172.20.0.0/20 range.

Thanks.


Edit: i forgot to creat new trunk with vti interface & chouse it by default. After that, all work properly.

Accepted Solution

  • alexey
    alexey Posts: 188  Master Member
    First Anniversary 10 Comments Friend Collector
    Answer ✓
    Options

    Edit: i forgot to creat new trunk with vti interface & chouse it by default. After that, all work properly.

All Replies

  • alexey
    alexey Posts: 188  Master Member
    First Anniversary 10 Comments Friend Collector
    Answer ✓
    Options

    Edit: i forgot to creat new trunk with vti interface & chouse it by default. After that, all work properly.

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @alexey

    It's good to know you had found the reason of it.😀

Security Highlight