Networking Forums

Networking Forums > Network Hardware > Network Routers > Zyxel Zywall 5

Reply
Thread Tools Display Modes

Zyxel Zywall 5

 
 
Daniele Cremonini
Guest
Posts: n/a

 
      02-25-2007, 10:24 PM
Hi,
I have almost created a VPN between two LANs that I'll call LAN_A and LAN_B.
RouterA can call RouterB and successfully establish a VPN between LAN_A
and LAN_B. The Zywall 5 are not directly connected to the internet
through two others routers.

A simple diagram follows.


LAN_A (192.168.0.X/255.255.255.0)
|
(192.168.0.1
Zywall5
192.168.1.2)
|
(192.168.1.1
RouterA
publicAddressA)
----internet----
(publicAddressB
RouterB
192.168.2.1)
|
(192.168.2.2
Zywall5 ---DMZ---10.1.2.1------10.1.2.2-Server1
10.1.1.253)
|
LAN_B 10.1.1.X/255.255.255.0


When I start a tracert command from LAN_A I can get into LAB_B in just 2
steps and have no problem whereas I can't establish any TCP connection
starting from LAN_B neither from DMZ. A couple of traceroutes from DMZ
towards two different machines in LAN_B network follows.

When I start a tracert command from Server1 locate in DMZ the behaviour
seems strange to me:
traceroute to 192.168.0.6 (192.168.0.6), 30 hops max, 40 byte packets
1 10.1.2.1 (10.1.2.1) 1 ms 1 ms 1 ms
2 192.168.2.1 (192.168.2.1) 2 ms 2 ms 2 ms
3 37.253.125.1 (37.253.125.1) 8 ms 8 ms 8 ms
4 10.3.7.194 (10.3.7.194) 9 ms 8 ms 9 ms
5 10.254.1.181 (10.254.1.181) 9 ms 9 ms 8 ms
6 * * *
......

traceroute to 192.168.0.11 (192.168.0.11), 30 hops max, 40 byte packets
1 10.1.2.1 (10.1.2.1) 1 ms 1 ms 1 ms
2 192.168.2.1 (192.168.2.1) 2 ms 2 ms 2 ms
3 37.253.125.1 (37.253.125.1) 8 ms 8 ms 12 ms
4 10.3.7.193 (10.3.7.193) 8 ms 9 ms 8 ms
5 10.254.1.177 (10.254.1.177) 9 ms 9 ms 8 ms
6 * * *
......

That's when I start a tracert command from LAN_B I can'tget into LAB_A
and while at the 3rd step I might thing the packet is travelling right
to the destination at the 4th step I'm almost sure the RouterB is
malfunctioning.
Question: anyone can explain to me why RouterB shows that behaviour?

Thank you
Daniele Cremonini
 
Reply With Quote
 
 
 
 
Daniele Cremonini
Guest
Posts: n/a

 
      02-25-2007, 11:45 PM
I have unchecked "ENABLE NAT TRAVERSING" in the VPN section.


Daniele Cremonini wrote:
> Hi,
> I have almost created a VPN between two LANs that I'll call LAN_A and
> LAN_B.
> RouterA can call RouterB and successfully establish a VPN between LAN_A
> and LAN_B. The Zywall 5 are not directly connected to the internet
> through two others routers.
>
> A simple diagram follows.
>
>
> LAN_A (192.168.0.X/255.255.255.0)
> |
> (192.168.0.1
> Zywall5
> 192.168.1.2)
> |
> (192.168.1.1
> RouterA
> publicAddressA)
> ----internet----
> (publicAddressB
> RouterB
> 192.168.2.1)
> |
> (192.168.2.2
> Zywall5 ---DMZ---10.1.2.1------10.1.2.2-Server1
> 10.1.1.253)
> |
> LAN_B 10.1.1.X/255.255.255.0
>
>
> When I start a tracert command from LAN_A I can get into LAB_B in just 2
> steps and have no problem whereas I can't establish any TCP connection
> starting from LAN_B neither from DMZ. A couple of traceroutes from DMZ
> towards two different machines in LAN_B network follows.
>
> When I start a tracert command from Server1 locate in DMZ the behaviour
> seems strange to me:
> traceroute to 192.168.0.6 (192.168.0.6), 30 hops max, 40 byte packets
> 1 10.1.2.1 (10.1.2.1) 1 ms 1 ms 1 ms
> 2 192.168.2.1 (192.168.2.1) 2 ms 2 ms 2 ms
> 3 37.253.125.1 (37.253.125.1) 8 ms 8 ms 8 ms
> 4 10.3.7.194 (10.3.7.194) 9 ms 8 ms 9 ms
> 5 10.254.1.181 (10.254.1.181) 9 ms 9 ms 8 ms
> 6 * * *
> .....
>
> traceroute to 192.168.0.11 (192.168.0.11), 30 hops max, 40 byte packets
> 1 10.1.2.1 (10.1.2.1) 1 ms 1 ms 1 ms
> 2 192.168.2.1 (192.168.2.1) 2 ms 2 ms 2 ms
> 3 37.253.125.1 (37.253.125.1) 8 ms 8 ms 12 ms
> 4 10.3.7.193 (10.3.7.193) 8 ms 9 ms 8 ms
> 5 10.254.1.177 (10.254.1.177) 9 ms 9 ms 8 ms
> 6 * * *
> .....
>
> That's when I start a tracert command from LAN_B I can'tget into LAB_A
> and while at the 3rd step I might thing the packet is travelling right
> to the destination at the 4th step I'm almost sure the RouterB is
> malfunctioning.
> Question: anyone can explain to me why RouterB shows that behaviour?
>
> Thank you
> Daniele Cremonini

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPSec VPN with 2 * Zyxel Zywall 2 Plus jjg Linux Networking 0 03-01-2010 05:00 PM
router zywall 10w freezing Joe Network Routers 0 01-28-2005 02:56 AM
How is the ZyXel Zywall 10 abspc Network Routers 0 01-21-2005 02:08 AM
Anyone here using a Zywall 2XW or 10W with 802.1x and Multiple APs? Lucas Tam Wireless Internet 1 04-15-2004 10:16 PM
Nildram, Zywall 643 and Zywall 10, VPN over ADSL ... Broadband 1 09-17-2003 08:39 AM



1 2 3 4 5 6 7 8 9 10 11