Multiple subnets with one IPSec VPN?
Recently replaced rusty 100mb/s firewall with shiny new USG 60, to be able use new ISP tariff plan with 300 mb/s and still be able to use IPSec tunnels to another site
Scheme is fairly easy, so no drawings, sorry
Local site - USG 60
192.168.6.0/24 - tel subnet
192.168.9.0/24 - computers subnet
Remote site - Cisco ASA
192.168.5.0/24 - tel subnet
192.168.10.0/24 - computers subnet
192.168.30.0/24 - servers subnet
The deployment scenario from Zyxel KB describes connecting ONE local subnet to ONE remote subnet, but i need to access all remote subnets from my local subnets. Now IPSec working and connecting telephone subnets only.
From previous experience using cisco / dlink firewalls, this is usually achieved by creating groups of objects(subnets) and then using them in VPN parameters, but the Zyxel interface explodes the brain
Could you please direct me in the right direction. Straight googling leads to nowhere.
Step-by step instruction will be best solution
Would greatly appreciate any help!
Thanks!
Scheme is fairly easy, so no drawings, sorry
Local site - USG 60
192.168.6.0/24 - tel subnet
192.168.9.0/24 - computers subnet
Remote site - Cisco ASA
192.168.5.0/24 - tel subnet
192.168.10.0/24 - computers subnet
192.168.30.0/24 - servers subnet
The deployment scenario from Zyxel KB describes connecting ONE local subnet to ONE remote subnet, but i need to access all remote subnets from my local subnets. Now IPSec working and connecting telephone subnets only.
From previous experience using cisco / dlink firewalls, this is usually achieved by creating groups of objects(subnets) and then using them in VPN parameters, but the Zyxel interface explodes the brain
Could you please direct me in the right direction. Straight googling leads to nowhere.
Step-by step instruction will be best solution
Would greatly appreciate any help!
Thanks!
0
Accepted Solution
-
Hi,
USG doesn't support multiple traffic selectors.
So you can use route-based VPN(VTI), if ASA OS is 9.7 or above.
5
All Replies
-
Hi,
USG doesn't support multiple traffic selectors.
So you can use route-based VPN(VTI), if ASA OS is 9.7 or above.
5
Categories
- All Categories
- 347 Beta Program
- 2.1K Nebula
- 114 Nebula Ideas
- 77 Nebula Status and Incidents
- 5K Security
- 44 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 65 Switch Ideas
- 901 WirelessLAN
- 33 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 326 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 831 Nebula FAQ
- 401 Security FAQ
- 219 Switch FAQ
- 190 WirelessLAN FAQ
- 45 Consumer Product FAQ
- 136 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 61 Security Highlight