- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-08-2012 12:56 AM
Hello All,
I am wondering if it is possible to add a second IP to a tunnel interface. I want to add some extra IPs to a tunnel interface (/28 subnet). To allow a remote party to connect to some servers in our internal network using NAT over IPsec tunnel. I have been looking at both CLI and GUI both cannot find it.
Kind regards,
Jorg
10-08-2012 01:03 PM
Hey Jorg,
You can define the subnet (/28) in the IP address section of the tunnel interface. Now from that subnet you use the rest of the other IP addresses to create the Destination NAT policies based on the requirements. I have tested this in my lab and everything works as expected. Let us know if you have any questions.
Khubaib
10-08-2012 02:03 AM
I think you are taking about the proxy id's here, correct me if I am wrong.
Tunnel Monitoring is used to keep a VPN tunnel communicating with the other VPN endpoint. If a tunnel monitor profile is created it will specify one of two action options if the tunnel is not available; wait-recover or fail-over.
For tunnel monitoring, under Network> Ipsec Tunnels > Advance Options, the destination ip-address would be a single Ip-address.
Secondary ip-address cannot be configure on the tunnel interface under Network > Interfaces > Tunnel
However, you can set proxy ids to achieve this where you can keep the local private subnet in "local" field and the remote private subnet under "remote" field. The same proxy ids also need to be set on the other side but the local and the peer subnets would be reversed.
Regards
10-08-2012 02:26 AM
The tunnel was allready setup and working and filled in the proxy ids for remote and local.
Have added one IP to tunnel inferface which we use for source nat to the other party. Works allready.
We just now want to make some servers accessible to the other party on a couple of IPs in the same /28 range. On our previous firewall we needed to create the interface first on every tunnel before we could destination nat. Is this also the case for PA.
Kind regards,
Jorg
10-08-2012 01:03 PM
Hey Jorg,
You can define the subnet (/28) in the IP address section of the tunnel interface. Now from that subnet you use the rest of the other IP addresses to create the Destination NAT policies based on the requirements. I have tested this in my lab and everything works as expected. Let us know if you have any questions.
Khubaib
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!