Hi,
we have a VERY simple setup where we have
1) Zyxel USG200 firewall, with 2 LAN's - one for WLAN and other for company LAN.
LAN: 192.168.0.1/24
LAN2: 192.168.2.1/24
Route 192.168.1.0/24 and 192.168.11.0/24 pointing to 192.168.2.2 (MSM720 internet interface)
2) behind that USG we have an MSM720, directly connected to a LAN-port of the FW
Internet-port (5) IP 192.168.2.2/24 (to LAN2 net of FW)
Access net ip 192.168.1.1/24
3) WLAN AP's directly connected to the MSM720
IP's 192.168.1.2-.5
4) One Guest WLAN, with no auth.
Now, I have tried two things
1) DHCP relay from the FW. This gives the clients correct IP's, but can't ping ANYTHING
2) DHCP from the MSM720, with subnet 192.168.11.0/24.
This pings both 192.168.1.1 and 192.168.2.2, but nothing further.
From LAN1 it's possible to ping both 192.168.2.2 and 192.168.1.1 through the FW, so routing is OK at least for those nets. Can't ping 192.168.11.x, though the routing goes all the way to 192.168.2.2
Any hints?