Zywall 110 Inter-VLAN (intra-Zone) routing problem

Options
Matthias_AUT
Matthias_AUT Posts: 10  Freshman Member
Friend Collector First Comment
edited April 2021 in Security
3 tagged VLANs on single port from switch, one additional LAN on firewall; All machines can access internet, all machines can ping and transfer data within VLAN and each individual VLAN can ping and connect to lan1.

Problem: Inter-VLAN routing is not working; In my understanding default behaviour should be to allow inter-VLAN traffic? I tried adding static routes, did not change anything; I disabled Security Policies/ Policy Control, did not help.

Every suggestions on what could be wrong appreciated.

Best regards, Matthias

Accepted Solution

«1

All Replies

  • Matthias_AUT
    Matthias_AUT Posts: 10  Freshman Member
    Friend Collector First Comment
    Options
    Forum did not like .conf, configuration file as .txt
  • PeterUK
    PeterUK Posts: 2,723  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited August 2020
    Options
    You shouldn't need static routes so remove that and try Policy Control off which should work.

    When you say Inter-VLAN you mean VLAN77 can't connect to VLAN587 ?

    unplug the WAN and see if that works
  • Matthias_AUT
    Matthias_AUT Posts: 10  Freshman Member
    Friend Collector First Comment
    Options
    PeterUK said:
    You shouldn't need static routes so remove that and try Policy Control off which should work.

    When you say Inter-VLAN you mean VLAN77 can't connect to VLAN587 ?

    unplug the WAN and see if that works
    Dear Peter, thanks for your help!

    1) I tried without the static routes and policy control off which also did not change connectivity (can still connect from VLAN77 to lan1 and from VLAN587 to lan1 but not from VLAN77 to VLAN587

    2) Yes exactly, VLAN77 can't connect to VLAN587 or VLAN883, same for the other VLANs, each can connect to lan1 but no other VLAN

    3) Unplugging the WAN resulted in lost connectivity from VLANs to lan1! Still no connectivity between VLANs...

    I really wonder why connectivity to lan1 is dependent on WAN being connected.

    Best regards, Matthias




  • PeterUK
    PeterUK Posts: 2,723  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited August 2020
    Options

    Make some zones for VLAN77, VLAN587 and VLAN883 then go to each VLAN interface and set zone from LAN1 to a given zone this way their not all on LAN1.

    Test again Policy Control off which should work.

    Will all VLAN's to zone LAN1 you would of needed to make a Policy Control rule from LAN1 to LAN1 and with each VLAN in its zone you make Policy Control rules from given zone to given zone.


  • PeterUK
    PeterUK Posts: 2,723  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    tested here between two VLANs with a ZyWALL 110 on V4.38 works fine

    VLAN4091 10.255.251.2 ping 10.255.252.2
    VLAN4090 10.255.252.2 replies to 10.255.251.2 
  • Matthias_AUT
    Matthias_AUT Posts: 10  Freshman Member
    Friend Collector First Comment
    edited August 2020
    Options
    PeterUK said:

    Make some zones for VLAN77, VLAN587 and VLAN883 then go to each VLAN interface and set zone from LAN1 to a given zone this way their not all on LAN1.

    Test again Policy Control off which should work.

    Will all VLAN's to zone LAN1 you would of needed to make a Policy Control rule from LAN1 to LAN1 and with each VLAN in its zone you make Policy Control rules from given zone to given zone.



    I made individual zones for each VLAN; like this?

    Tested with policy control off; I cannot ping between VLANs and neither to lan1 which works when all are in the same zone.
    I can (and always could) ping all the gateways, but not the machines connected to them.

    I tried both variants with policy control, all on zone LAN1 and LAN1toLAN1 as well as separate zones and LAN1toVLANxxx, did not work;

    I wonder if there is something fundamentally wrong with the way I set up the VLANs, this is how it looks
    And all the VLANs itself:

    Thanks for your effort!

    Best regards, Matthias

    EDIT: Latest FW Version, V4.38
  • Matthias_AUT
    Matthias_AUT Posts: 10  Freshman Member
    Friend Collector First Comment
    Options
    PeterUK said:
    tested here between two VLANs with a ZyWALL 110 on V4.38 works fine

    VLAN4091 10.255.251.2 ping 10.255.252.2
    VLAN4090 10.255.252.2 replies to 10.255.251.2 
    Dear Peter, could you please upload the conf file of your working Zywall 110 so I can check for differences to my config?

    Thanks a lot,
    Matthias

  • PeterUK
    PeterUK Posts: 2,723  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    I can't upload my config as I like to keep it private.

    Can you change the port role so LAN1 is not linked to other ports for testing.


  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Matthias_AUT,

    FW: 4.38(AAAA.0)

    I applied your configuration file to a ZyWALL 110 to run the test.

    Inter-VLAN routing is working successfully even if firewall is enabled.

    PC1 in vlan587 is able to ping PC2 in vlan883 and vice versa.

    Hence, there is no problem with the settings on ZyWALL110.

    Try to check the configuration on the switch.

    Topology:

    ZyWALL 110(P4)----(P10)GS2210(P2)-----PC1(128.130.77.66)

                                                          (P3)-----PC2 (128.130.77.98)




  • Matthias_AUT
    Matthias_AUT Posts: 10  Freshman Member
    Friend Collector First Comment
    Options

    Topology:

    ZyWALL 110(P4)----(P10)GS2210(P2)-----PC1(128.130.77.66)

                                                          (P3)-----PC2 (128.130.77.98)

    Hi Zyxel_Emily, are P4 and P3 in your topology different physical ports on the Zywall? My VLANs come all in as trunk on P4, can this be the problem?

    Do I have to configure virtual interfaces for the VLANs?

    I have no idea what could be wrong with the switch settings as all 3 VLANs successfully connect to the Internet, any suggestions?

    Best regards, Matthias

Security Highlight