Comments
-
You have the old USG50 that only support policy-based IPSec. So that you need to use policy route on both side. Static route is not work on your case.
-
What's the firewall model on both side ? Zyxel firewall with ZLD 4.20 or above can support both policy-based and route-based IPSec VPN. 1.For policy-based IPSec (all ZLD version) (1)on side a, add a policy route src.: side a LAN2 subnet to dst.: side b LAN3 subnet, next-hop: the IPSec tunnel to side b (2)on side b, add a…
-
I just found some old news mention ammyy wbe sites was compromised last year. Not sure if all the malicious code removed from the web sites. ?
-
Any web authentication rules there ? How about the simple ping to LAN server ?
-
Do you configure the firewall rule to allow the VPN clients IP address to access LAN of USG60W ?
-
If USG60W is behind NAT, Here the recommend solution, On the NAT router need to configure port forwarding UDP500,UDP4500 mapping to WAN IP of USG. On USG110, you can use site-to-site with static IP or DDNS for USG60W. If you cannot configure the NAT router. Then, on USG110 using site-to-site with dynamic peer for USG60W.…
-
Hi @LeoSoft, Login ATP via SSH or Console and type-in the following CLI commands, # configure terminal Router(config)# no ip http secure-server auth-client Router(config)# write Router(config)# exit # exit
-
I'm wondering if SonicWall has proxy arp behavior. Here something you can check, 1.On USG40 using CLI, # ping 92.208.175.193 # show arp-table, to check if you get the right MAC address of Cisco gateway 2.On USG40 GUI, capture wan interface traffic Go to MAINTENANCE -> Diagnostics -> Packet Capture select you wan interface,…
-
The arp learning of VPN100 will not working as expected. I suggest to configure VPN100 like this, (1) LAN as network 192.168.11.128/25 (you can have 125 hosts IP under LAN) (2) Configure proxy-arp on wan1 for 192.168.11.128/25 (3) Disable WAN Trunk default SNAT
-
Any reason that WAN and LAN need to be in the same IP subnet(11.X/24) ? That will be issue if VPN100 is acting as a router.
-
USG support IGMP proxy over VTI IPSec VPN tunnel interface. But it's limit on what's kind of multicast application you using.
-
Hi @Technician0815, If you can provide a topology. That will help to understand the case.
-
Orange should tell you which 212.X.X.X IP is the default gateway of this IP block. And if they can provide the example configuration of Cisco router is also help to know how to map the settings on USG. Then based on the topology, comes other questions of the requirement: Do you need the hosts behind USG310 & USG60 can…
-
Hi, From the ATP200 datasheet, here the APs can be managed by ATP controller function. I also check the product page of NWA1123-ACV2 & NWA1123-AC HD on Zyxel web site. "https://www.zyxel.com/products_services/802-11ac-Dual-Radio-Ceiling-Mount-PoE-Access-Point-NWA1123-ACv2/"…
-
212.x.x.176 - 212.x.x.183 /29 176 stands for network and 183 for broadcast, so we've got available: 212.x.x.177 - 212.x.x.182 But what is the default gateway IP address of this IP block ?
Master Member