Zyxel ZyWALL USG 2000 [44/185] Accessing ipsec vpn peer subnet from ssl

Zyxel ZyWALL USG 20W [44/185] Accessing ipsec vpn peer subnet from ssl
ZyWALL USG Support Notes
44
All contents copyright (c) 2010 ZyXEL Communications Corporation.
Step4. Go to Configuration > Network > Routing, add one policy route as below:
Source: 192.168.1.33(server)| Destination: any| Next hop: <the newly added WAN
trunk>| SNAT: None.
Please not that we set the SNAT to be None, because we still need the 1:1 NAT
mapping to translate the servers outgoing traffic source address.
1.11. Accessing IPSec VPN Peer Subnet From SSL
VPN Clients
1.11.1. Application Scenario
USG ZyWALL is placed as the HQ gateway. Branch office builds IPSec VPN tunnel
to HQ office. Local subnets of branch office and HQ office can communicate via the
IPSec VPN tunnel.
SSL VPN client builds SSL VPN full tunnel to HQ to access HQ local subnet
resources. Besides, the SSL VPN client also wants to access Brach office local
resources first via SSL VPN full tunnel to HQ, then via the IPSec VPN tunnel to
branch office.

Содержание

Скачать