Allow two different internet sources to OpenVPN appliance
Options
Right now I have two separate WANs which I'd like to set up so that either one will allow my users to connect to our vpn. I'm testing with port 3389 because it's a little easier. The users client will try WAN1 first and then WAN2 if there is an issue.
WAN1 is on G1 and WAN2 is on G2 LAN is G3.
From my home pc (PC2) I connect to WAN2's public ip which is forwarded to PC1 and the vpn log says "ACCESS FORWARD" so I know it at least got to PC1, but it looks like it wasn't able to talk back to PC2. I'm assuming it came in WAN2, but went back out WAN1.
My thoughts are something needs to change with the policy routes, but that's just a guess.
WAN1 is on G1 and WAN2 is on G2 LAN is G3.
From my home pc (PC2) I connect to WAN2's public ip which is forwarded to PC1 and the vpn log says "ACCESS FORWARD" so I know it at least got to PC1, but it looks like it wasn't able to talk back to PC2. I'm assuming it came in WAN2, but went back out WAN1.
My thoughts are something needs to change with the policy routes, but that's just a guess.
0
All Replies
-
It looks like I answered my own question. I had a policy route for each wan with the next hop being WAN1 and WAN2 respectively. I added a third at the top and set the next hop to auto which seems to be working now.0
-
Hi @ACS
In your scenario, the NAT rule is working on WAN1.
So it means DRP server must response by WAN1 interface.
If policy route forced traffic pass through by WAN2, then PC2 will drop packets.
It is because PC2 receives response packets with unknown IP address.
0
Categories
- All Categories
- 385 Beta Program
- 2.1K Nebula
- 116 Nebula Ideas
- 80 Nebula Status and Incidents
- 5.1K Security
- 74 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 70 Switch Ideas
- 907 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 210 Service & License
- 334 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.9K FAQ
- 886 Nebula FAQ
- 415 Security FAQ
- 228 Switch FAQ
- 198 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 137 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 73 About Community
- 63 Security Highlight