![background image](/i/zyxel/144701/zyxel-zywall-2wg-ee/h/zyxel-zywall-2wg-ee-264.png)
Chapter 12 Firewall Screens
ZyWALL 2WG User’s Guide
264
From VPN To VPN Packet Direction
From VPN To VPN
firewall rules apply to traffic that comes in through one of the ZyWALL’s
VPN tunnels and terminates at the ZyWALL (like for remote management) or goes out
through another of the ZyWALL’s VPN tunnels (this is called hub-and-spoke VPN, see
for details). The ZyWALL decrypts the traffic and applies the
firewall rules before re-encrypting it or allowing the traffic to terminate at the ZyWALL.
In the following example, the
From VPN To VPN
default firewall rule silently blocks the
traffic that the ZyWALL receives from any VPN tunnel (either A or B) that is destined for the
other VPN tunnel or the ZyWALL itself. VPN traffic destined for the DMZ is allowed
through.
Figure 167
From VPN to VPN Example
Asymmetrical Routes
If an alternate gateway on the LAN has an IP address in the same subnet as the ZyWALL’s
LAN IP address, return traffic may not go through the ZyWALL. This is called an
asymmetrical or “triangle” route. This causes the ZyWALL to reset the connection, as the
connection has not been acknowledged.
You can have the ZyWALL permit the use of asymmetrical route topology on the network (not
reset the connection).
Allowing asymmetrical routes may let traffic from the WAN go directly to the LAN without
passing through the ZyWALL. A better solution is to use IP alias to put the ZyWALL and the
backup gateway on separate subnets.
Asymmetrical Routes and IP Alias
You can use IP alias instead of allowing asymmetrical routes. IP Alias allow you to partition
your network into logical sections over the same interface.