ZyXEL Communications ZyWALL USG Series Application Notes page 142

Unified security gateway
Hide thumbs Also See for ZyWALL USG Series:
Table of Contents

Advertisement

• My Address: 10.0.0.1
• Peer Gateway Address: 10.0.0.2
VPN Connection (VPN Tunnel 1):
• Local Policy: 192.168.168.0~192.168.169.255
• Remote Policy: 192.168.167.0/255.255.255.0
• Disable Policy Enforcement
VPN Gateway (VPN Tunnel 2):
• My Address: 10.0.0.1
• Peer Gateway Address: 10.0.0.3
VPN Connection (VPN Tunnel 2):
• Local Policy: 192.168.167.0~192.168.168.255
• Remote Policy: 192.168.169.0/255.255.255.0
• Disable Policy Enforcement
Branch Office B (ZLD-based USG):
VPN Gateway:
• My Address: 10.0.0.3
• Peer Gateway Address: 10.0.0.1
VPN Connection:
• Local Policy: 192.168.169.0/255.255.255.0
• Remote Policy: 192.168.167.0~192.168.168.255
• Disable Policy Enforcement
3.3.1 What Can Go Wrong
Consider the following when implementing a hub-and-spoke VPN.
• This example uses a wide range for the ZyNOS-based USG's remote network, to use a narrower
range.
• The local IP addresses configured in the VPN rules should not overlap.
• The hub router must have at least one separate VPN rule for each spoke. In the local policy ,
specify the IP addresses of the hub-and-spoke networks with which the spoke is to be able to
have a VPN tunnel. This may require you to use more than one VPN rule.
• T o have all Internet access from the spoke routers to go through the VPN tunnel, set the VPN
rules in the spoke routers to use 0.0.0.0 (any) as the remote IP address.
• Your firewall rules can still block VPN packets.
• If the ZLD-based USGs' VPN tunnels are members of a single zone, make sure it is not set to block
intra-zone traffic.
• The ZyNOS based USGs don't have user-configured policy routes so the only way to get traffic
destined for another spoke router to go through the ZyNOS USG's VPN tunnel is to make the remote
policy cover both tunnels.
• Since the ZLD-based USGs automatically handle the routing for VPN tunnels, if a ZLD-based USG
USG is a hub router and the local policy covers both tunnels, the automatic routing takes care of
it without needing a VPN concentrator .
141

Advertisement

Table of Contents
loading

Table of Contents