Site 2 Site VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Site 2 Site VPN

L2 Linker

I have an issue where we have ike traffic comeing from the end point which is being allowed but the ipsec-esp is being caught by the deny all rule. The strange thing is that the the rule to allow ike and ipsec-esp is on the same rule.

 

We do carry out NAT on the public IP for some ports , is this this the issues Untitled.png

 

Can any one please point me in the right direction

 

1 accepted solution

Accepted Solutions

As @_slv_ already pointed out your rule is likely malformed so the traffic isn't getting caught. A picture of the rule would do wonders here over the logs. 

View solution in original post

4 REPLIES 4

L4 Transporter

Please show us that rule. What about port/services - are You using defualt one?

 

 

Regards

Slawek

L6 Presenter

Based on the external source IP (your remote office) temporary allow all traffic (any) and observe the behaviour. ESP has no port number so no it is not a NAT issue. 

As @_slv_ already pointed out your rule is likely malformed so the traffic isn't getting caught. A picture of the rule would do wonders here over the logs. 

Hello,

On my tunnels I have the following applications allowed so they are not blocked. I also whitelist the source/destination IP's for my site to site vpns for added protection:

 

Capture.JPG

 

Hope that helps.

  • 1 accepted solution
  • 2699 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!