Quantcast
Channel: ZyXEL forum - dslreports.com
Viewing all articles
Browse latest Browse all 518

How to Route Internet over IPsec Tunnel

$
0
0
i have one USG110 and one USG60 where the USG110 is located in China and the USG60 in Hongkong. As the internet in China is a bit restricted i would like to route the internet for certain ip subnets(for example google ip subnets for which i already created a group of all know google ip's) from to USG 110 over the USG 60. the IPSEC tunnel between USG110 and USG60 is working and i can ping the USG 60 lan ip from a computer connected to the USG110. But i cant ping an IP in the internet. USG 110 local ip: 192.168.1.221 USG 60 local IP: 192.168.43.1 from USG110 site: ping 192.168.43.1 OK ping 8.8.8.8 request timed out tracert 8.8.8.8 Tracing route to google-public-dns-a.google.com [8. over a maximum of 30 hops: 1 1 ms 1 ms 1 ms 192.168.1.221 2 * * * Request timed out. 3 * * * Request timed out. From the tracert it looks like a routing problem as 2nd hop should be 192.168.43.1 (USG60) I found this topic in the Forum and i folowed its configuration buts its not working for me: http://www.dslreports.com/forum/r29763606-How-to-Route-Internet-over-IPsec-Tunnel USG60 policy route (Use IPv4 Policy Route to Override Direct Route activated) 1 incoming: Tunnel HKtoCN, Source: China Subnet, Destination LAN1_Subnet, Next-Hop: Gateway USG60, DSCP Preserve, SNAT: none 2 incoming: Interface Wan1, Source: any, Destination China Subnet, Next-Hop: Tunnel HKtoCN, DSCP Preserve, SNAT: none 3 incoming: Tunnel HKtoCN, Source: China Subnet, Destination any, Next-Hop: Trunk SYTEM_DEFAULT_WAN_TRUNK , DSCP Preserve, SNAT: outgoing interface 4 incoming: any (excluding zywall), Source: LAN1_Subnet, Destination China Subnet, Next-Hop: Tunnel HKtoCN, DSCP Preserve, SNAT: none USG110 policy route config (Use IPv4 Policy Route to Override Direct Route activated) 1 incoming:any (excluding zywall), Source: LAN1_subnet, Destination Hongkong_Subnet, Next-Hop: Tunnel HKtoCN, DSCP Preserve, SNAT: none 2 incoming: any (excluding zywall), Source: LAN1_subnet, Destination Google_Subnets, Next-Hop: Tunnel HKtoCN, DSCP Preserve, SNAT: none does anyone have an idea whats missing here that the traffic to google subnet is not routed to the USG60? thanks Max

Viewing all articles
Browse latest Browse all 518

Trending Articles