Friday, January 11, 2019

Zyxel USG200 and USG100 IPSec VPN SNAT to allow ARD

I have a IPSec tunnel configured between USG200 and USG100. USG100 has a 10.1.100.0/24 network behind its LAN1. USG200 has a 10.1.1.0/24 network behind its LAN1 which host different services on few Macs. Everything works fine and there is communication all the way between two subnets. However, to save power on Macs, we want to implement sleep or wake-up feature from our remote network (10.1.100.0/24). But the problem is Apple Remote Desktop (ARD) allows Mac to sleep or wake-up if the machines are on the same subnet.

I tried to use SNAT on USG100 and NATing the IPs to few redundant IPs in 10.1.1.0/24 range. However, I could not establish any communication between the sites. Is there an easier way to achieve this? I know the rule of thumb of not having same subnets on different ends of IPSec tunnel, but is there a way we can mask the IPs and make ARD believe we are on the same subnet?



No comments:

Post a Comment