www.zyxel.com Introduction This guide will explain how to configure a site-to-site VPN connection as shown in the picture below: In the above scenario the clients at the Branch office wants to be able to access the Headquarters entire LAN subnet and vice versa. The setup will be the same regardless what ZyWALL USG model you are using.
www.zyxel.com ZyWALL USG 100 Creating the address objects Go to Configuration Object Address and click the button. Now create a Subnet address that contains the LAN Subnet of the opposite ZyWALL USG as shown in the picture below: Creating VPN Gateway Go to Configuration ...
www.zyxel.com Creating VPN Connection Go to Configuration VPN IPSec VPN VPN Connection and click button. Enable the Connection. Under Application Scenario choose Site-to-site. Make sure that you select the correct VPN Gateway, in this case Headquarters. In Local policy select the LAN Subnet of the ZyWALL USG 100.
www.zyxel.com ZyWALL USG 200 Creating the address objects Go to Configuration Object Address and click the button. Now create a Subnet address that contains the LAN Subnet of the opposite ZyWALL USG as shown in the picture below: Creating VPN Gateway Go to Configuration ...
www.zyxel.com VPN Connection Go to Configuration VPN IPSec VPN VPN Connection and click button. Enable the Connection. Under Application Scenario choose Site-to-site. Make sure that you select the correct VPN Gateway, in this case Branch_Office. In Local policy select the LAN Subnet of the ZyWALL USG 200.
www.zyxel.com Establish connection Both ZyWALL USG’s are now configured. The only thing left, is to establish the VPN connection. This can be done manually by selecting your VPN connection and clicking the Connect button in Configuration VPN IPSec VPN VPN Connection. Alternatively you can edit the VPN Connection rule, click Show Advance Settings and enable Nailed-Up.