|
ZyWall USG 100 disable Split tunnel optionHi there I would like to configure IPsec tunnel so that everything is routed through the tunnel. I checked disable split tunnel option (in greenbow client) . USG is 2.2 AQQ6, and I created two policy route user-any, incoming-IPSec tunnel, destination-any, next hop-TRUNK user-any, incoming-any, destination-LAN, next hop-IPsec tunnel
And it is not working ! Can someone help me to configure it ? Thanks |
|
|
Hi. Do you want that VPN-clients reach internet through the VPN? |
|
|
Hi yes I would like to do that. Clients should access internet through our company. I checked in greenbow IPsec client (Disable split tunnel) but still nothing. |
|
|
Listen, try setting remote as 0.0.0.0/32 Declare DNS servers in remote networks. Does it work? |
|
|
Hi, yes I did that, all traffic now goes through the tunnel, but I have not some sort of a problem. If I have a local LAN, and I am connected with IPsec tunnel to remote location from that LAN, all the traffic is routed through the tunnel, and I cannot access local resources any more . Is that normal or not ? Thanks |
|
BranoI hate Vogons MVM join:2002-06-25 Burlington, ON (Software) OPNsense Ubiquiti UniFi UAP-AC-PRO Ubiquiti NanoBeam M5 16
|
to Aleksandar
said by Aleksandar:user-any, incoming-IPSec tunnel, destination-any, next hop-TRUNK user-any, incoming-any, destination-LAN, next hop-IPsec tunnel Keep in mind one rule for all firewall, routing and other tables: All tables (rules) are evaluated from top to bottom and when there's a match it is executed/applied and no other rules are processed. So the order (position) matters. So make sure you check all your policy and firewall rules to ensure they're in right order. Suggest you post screenshot of your firewall and policy route tables. |
|
1 edit |
to Aleksandar
Well, if you want that all shoud be reached from remote, it is. removed by me Which is your topology? |
|
|
topology location 1 int---USG 100---LAN | DMZ topology location 2 LAN1-----USG 20----int -----ipsec-----int---USG50---LAN2 I managed for location 1 to configure, I am testing it now, but which routing policy I need to create for location 2 ? on USG 20 - from lan1 to tunnel if destination is LAN2 on USG 50 - from lan2 to tunnel if destination is LAN1 anything else ? I attached print screen of USG 100 settings
|
|
Aleksandar |
Hi there, I still have a problem with no split tunnel option , now entire traffic is rerouted to tunnel, but then I lost my connection with LAN resources.... Please help |
|