Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Site To Site Vpn (zyxel/zywall) Ip Routing

Card image cap

Hi all,

What I'm trying to do doesn't seem all that complex but I've spent untold numbers of hours now trying to get it to work (with router mfr/AI answers/etc) and am losing my mind.

Here's our situation:

We have a new branch office opening up very soon. Our current topology uses managed SD wan to route between offices and our datacenter. With this, our provider could generally add routing changes on their end easily. In our scenario, however, they did not have enough lead time to deploy SD wan prior to opening (also not enough time to do the fiber install) we are temporarily using a standard cable connection and a zywall flex 500H in hopes of bypassing SDwan via VPN. This new office "RH" has a local subnet of 192.168.150.0/24 and lets call the WAN address 1.2.3.4. The zywall LAN address is 192.168.150.217 and is acting as default gateway.

The other end of this tunnel (at our data center "CL") uses local subnet 192.168.170.0/24 with WAN 5.6.7.8 and LAN address 192.168.170.220. At this site we use a cisco business layer 3 switch with IP 192.168.170.1. As it stands now I have a simple policy based site to site VPN between RH (192.168.150.0/24) and CL (192.168.170.0/24). The VPN is connected reliably and these two subnets communicate just fine (that's the easy part I guess)

Where it gets a little trickier is that the server subnet we need to reach from RH is 10.0.150.0/24. There is a VLAN for this subnet (150) on the 170.1 switch. physical ports on this switch lead to an esxi hypervisor (NIC teaming) currently all the virtual servers use default gateway 10.0.150.1 (a sub-interface IP on our managed SDwan gateway) To work around this, I assigned vlan 150 on the switch the IP of 10.0.150.2 and can add static routes on the servers telling them to send 192.168.150.0/24 traffic to either 192.168.170.1 or 10.0.150.2.

To put it in simplest terms:

On the 192.168.150.x subnet we can ping any address on the remote subnet (192.168.170.x) just fine in both directions. We need to be able to initiate traffic from 192.168.150.x subnet to 10.0.150.x. If I could just make make the next hop on the 170.220 router to 170.1 (the switch) i think I could figure it out from there or maybe route from the zywall itself. problem is that no matter how many policy routes etc I try to make, my traceroutes aren't making it as far as the remote subnet.

I apologize if this is unclear. my mind is shot, ive spent days now trying to figure this out and was at our datacenter until 4:30 am and can still hear whirring fans in my head. I only have a few days to sort this out before we open or it will be very bad. I can clarify further or provide screen shots as needed (there were too many to include all). I'm sleep deprived enough that I'm not my sharpest; The other ideas I have i suspect are more complex than necessary.

If anyone has any advice I would greatly appreciate it thanks!

submitted by /u/Resurget-Cineribus
[link] [comments]