republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » ZyXEL » USG 100 VPN Troubles
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
New firmware is out ZyWALL 2 Plus_4.04(XU.7)C0 »
« ZyWall USG100 to Greenbow VPN  
AuthorAll Replies


bbarrera
Premium,MVM
join:2000-10-23
Sacramento, CA
clubs:
·SureWest Internet

reply to mudtoe
Re: USG 100 VPN Troubles

you should ping between LAN computers, there are routerOS and firmware dependent issues when doing so from CLI.

practically EVERYTHING on USG is controlled by policy routes, even stuff you would expect to work using the static routes setup by interfaces. Its a painful but true, and the original beta testers were ignored. That said the USG (ZLD Linux based) is overall much better than original Zywall (ZyNOS based)

mudtoe

join:2005-10-09
Cleveland, OH

said by bbarrera See Profile :

...practically EVERYTHING on USG is controlled by policy routes, even stuff you would expect to work using the static routes setup by interfaces. Its a painful but true, and the original beta testers were ignored. That said the USG (ZLD Linux based) is overall much better than original Zywall (ZyNOS based)
It seems like they have made things much more complicated. I suppose that there is more flexibility, but the documentation leaves a WHOLE LOT to be desired with regard to explaining how all these options interact with each other, and supplying some common configuration setup examples.

I do believe that you are right in that I should go back to the customer's site and try to resolve this by using a PC on their lan rather than trying to just use the USG100 routers themselves as ping points. That would eliminate any goofy things regarding the router as an endpoint, like the swDevTri thing for the Z35 that was mentioned above.

mudtoe

mudtoe

join:2005-10-09
Cleveland, OH

I tried the changes at the customer site after implementing policy routes for the VPN, and it worked just fine. Also, as an FYI, if you want to be able to test the tunnel with pings from the Zywall itself, you have to add a separate policy route for the Zywall (and a firewall rule), which is why it wasn't working when I tried pinging through the VPN via an SSH session to the Zywall.

Thanks all for the assistance.

mudtoe


bbarrera
Premium,MVM
join:2000-10-23
Sacramento, CA
clubs:
policy routes are the key to solving many issues on USG series.

mudtoe

join:2005-10-09
Cleveland, OH

said by bbarrera See Profile :

policy routes are the key to solving many issues on USG series.
Do the policy routes make completely obsolete the IP addresses in the VPN definitions themselves if you are using two USG series routers for the VPN? What I mean is can you route any traffic you want through the tunnel by using policy routes, even if the addresses involved were not explicitly defined in the VPN definition?

mudtoe


SmurfLurf

join:2007-12-18
Whittier, CA

said by mudtoe See Profile :

said by bbarrera See Profile :

policy routes are the key to solving many issues on USG series.
Do the policy routes make completely obsolete the IP addresses in the VPN definitions themselves if you are using two USG series routers for the VPN? What I mean is can you route any traffic you want through the tunnel by using policy routes, even if the addresses involved were not explicitly defined in the VPN definition?

mudtoe
That's correct. You can force any traffic you like through the VPN tunnel, but it will only be passed if the checkbox for 'Policy Enforcement' is not checked. Of course you'll need additional policy routes in place to direct the traffic.
-
Forums » Equipment Support » Hardware By Brand » ZyXELNew firmware is out ZyWALL 2 Plus_4.04(XU.7)C0 »
« ZyWall USG100 to Greenbow VPN  


Tuesday, 01-Dec 14:29:50 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [62] Baltimore To Ban Lazy Cable Installs
· [60] Comcast Releasing Promised Usage Meter
· [54] Broadband Killed The Game Console
· [41] Rogers Unveils The ISP Dream Model
· [38] Rural Carriers Quickly Embracing Fiber
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [32] Charter Exits Chapter 11
· [24] Midcontinent Socked With Easement Lawsuit
· [20] Vivendi Agrees, Comcast/NBC Deal Soon
· [18] ACTA: Global Three Strikes
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Phish] email from CDC "personal vaccination profile" [Spam, Scam and Phishbusters]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [Rant] called out sick! [Rants, Raves, and Praise]
· buying a one way ticket [General Questions]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· Fun screwing with PuG raids. [World of Warcraft]
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]
· [Internet] Gaming problem for "Heroes of Newerth" ( New bell Upd [Bell Canada]