Setting up Hardware Site to Site VPN

kraftjefferyp

Prominent
Jan 25, 2018
1
0
510
Using No-IP service to connect two Zyxcel USG 20 boxes is it possible for them to appear on the same subnet to devices on both ends (tivo)



 
Solution
It's called Branch VPN. You configure in the router endpoints. I do this all the time with Watchguard VPNs. However, Zyxel is another story all together. I've used Zyxel a few times and had to drop it because it was lacking features back then that came with standard firewalls.

However, only way you can do this is either with two static IPs, or if the firewall supports No-IP. I know a lot of firewalls nowadays allows for DYNDNS but I havn't seen any that allows for no-ip entries.

So unless you go with a static IP. I don't think you are going to be able to configure this type of setup.

https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=015405&lang=EN
It's called Branch VPN. You configure in the router endpoints. I do this all the time with Watchguard VPNs. However, Zyxel is another story all together. I've used Zyxel a few times and had to drop it because it was lacking features back then that came with standard firewalls.

However, only way you can do this is either with two static IPs, or if the firewall supports No-IP. I know a lot of firewalls nowadays allows for DYNDNS but I havn't seen any that allows for no-ip entries.

So unless you go with a static IP. I don't think you are going to be able to configure this type of setup.

https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=015405&lang=EN
 
Solution
It depends to a point on how you set it up. To actually have the 2 locations really on the same subnet you need a vpn function called L2TPv2. This is not supported by a lot of devices and is cpu intensive because it is passing all layer 2 traffic.

Your other options are full routed which of course has different subnets. The in between method assigns a ip address from the remote subnet to a local device. This is what you see used in consumer routers. It depends which direction the traffic is going. From the remote network the local machines appear to all be behind that ip. Unfortunately it has the same issue as NAT. If you only have a single device you might trick it into mapping the ip 1-1 to a internal device. This depends on the router having a feature to do that.

I do not know about zyxel stuff. If you can get l2tpv2 that is your best option if you have enough cpu capacity.