When creating 1:1 NAT rules for local hosts, these local hosts become unreachable through VPN IPSec.
Zyxel_Charlie
Posts: 1,034 Zyxel Employee
The virtual server function is a "port forwarding" function.
The 1:1 NAT function is "forwarding all traffic" to the local server.
When using "1:1NAT", the traffic can't pass through to the tunnel because all traffic passes through the WAN interface.
In "packet flow explore", the priority of 1-1 SNAT is higher than site to sitesite-to-site VPN when 1:1 NAT is enabled.
To solve this problem, please reorganize the order of the routing priority.
For legacy models with ZLD 3.30 platform, use the following CLI command.
ip route control-virtual-server-rules activate
For new USG/ZyWALL series with ZLD 4.13, enable "Use Static-Dynamic Route to Control 1-1 NAT Route" on GUI.
Tagged:
0
Categories
- All Categories
- 338 Beta Program
- 2.1K Nebula
- 112 Nebula Ideas
- 75 Nebula Status and Incidents
- 5K Security
- 38 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 64 Switch Ideas
- 881 WirelessLAN
- 32 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 325 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 803 Nebula FAQ
- 397 Security FAQ
- 212 Switch FAQ
- 188 WirelessLAN FAQ
- 44 Consumer Product FAQ
- 135 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 60 Security Highlight