This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setup Question LAN/WAN VPN

Hi !

I'm quite new to XG Firewall. I've got the following Setup:

XG Softwarebased setup on 2 Lan Card PC

Port 1 LAN with Range from 192.168.1...

Port 2 WAN with Statik IP 192.168.3.... getting it from Router LAN

Router with static IP Adress 77.119 ... connected to WAN (Mobile Carrier). 

The Router forwards relevant Ports for RD Services and so on to Port 2 of XG

Everything works fine except SSL-VPN - this is set up properly to forward into LAN Zone.

I cannot seem to setup a connection from outside of the network. I forward Port 8443 for SSL-VPN from the router to Port 2 of XG with no effect.

The client seems to cannot setup a connection since it always tries to reach 192.168.3... and not the external router IP from the carrier.

Actually I have no idea where to set this up. Can anyone help here?

Regards

hinze



This thread was automatically locked due to age.
Parents
  • Hey Hinze,

    In order to properly specify that your clients attempt the SSL VPN connection via your upstream ISP router's WAN IP, please fill in the "Override Hostname" field with this IP.

    Configure > VPN > top right "Show VPN Settings" 

    Please note that updating the settings in this menu will require a re-download of the SSL VPN configuration from the user portal.

    Let me know if you run into any issues.

    Regards,

  • Thanks Flo! 

    works perfectly fine! 

    I'can get in the SSLVPN IP Range now, I've setup the vpn rules VPN to LAN - LAN to VPN and general network policiees LAN to all zones as suggested in the documentation but I'll always get an VPN Range IP for my remote device and not the one from the local subnet that I specified .

    Is there anything more I can do to be forwarded to the local subnet?

    I've studied several community articles on this matter but none seems to help.

    Strange...

  • "t I'll always get an VPN Range IP for my remote device and not the one from the local subnet that I specified ."

     

    That is how this works.

    Basically you get a IP from the Pool and for every other device attached to XG, you are just a other subnet. 

    The client does not get any IP of any Lan Client. Instead XG will just route the traffic to the correct network. 

    Can you post some screenshots of your VPN config? Maybe there is a mistake. 

Reply
  • "t I'll always get an VPN Range IP for my remote device and not the one from the local subnet that I specified ."

     

    That is how this works.

    Basically you get a IP from the Pool and for every other device attached to XG, you are just a other subnet. 

    The client does not get any IP of any Lan Client. Instead XG will just route the traffic to the correct network. 

    Can you post some screenshots of your VPN config? Maybe there is a mistake. 

Children