USG40: disable the web authentification on the WAN side, but keep it internally (LAN)

Options
2»

Comments

  • PeterUK
    PeterUK Posts: 2,724  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    If your wanting to do SSL VPN you will be allowing WAN to ZyWall on port 443 is this what your doing? 

  • ictforever
    ictforever Posts: 15  Freshman Member
    Friend Collector First Comment
    Options
    I have a IPSEC VPN configured from Office to Branch. I don't know which port that is to be honest.
    What I do know, something in the policy rule WAN to Zywall is disabling my vpn connection when I disable it.
  • PeterUK
    PeterUK Posts: 2,724  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    So you need a rule for WAN to Zywall with service ports for the IPSEC VPN so you don't allow all service ports.

    You could do it as:

    first rule WAN to Zywall deny to service HTTPS

    second rule WAN to Zywall allow all

  • ictforever
    ictforever Posts: 15  Freshman Member
    Friend Collector First Comment
    Options
    That did the trick. What also worked is to remove the https from the default group.

    Thanks @PeterUK

Security Highlight