- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-22-2017 05:41 AM
I have an issue where we have ike traffic comeing from the end point which is being allowed but the ipsec-esp is being caught by the deny all rule. The strange thing is that the the rule to allow ike and ipsec-esp is on the same rule.
We do carry out NAT on the public IP for some ports , is this this the issues
Can any one please point me in the right direction
06-22-2017 06:55 AM
As @_slv_ already pointed out your rule is likely malformed so the traffic isn't getting caught. A picture of the rule would do wonders here over the logs.
06-22-2017 06:18 AM
Please show us that rule. What about port/services - are You using defualt one?
Regards
Slawek
06-22-2017 06:49 AM
Based on the external source IP (your remote office) temporary allow all traffic (any) and observe the behaviour. ESP has no port number so no it is not a NAT issue.
06-22-2017 06:55 AM
As @_slv_ already pointed out your rule is likely malformed so the traffic isn't getting caught. A picture of the rule would do wonders here over the logs.
06-22-2017 07:14 AM
Hello,
On my tunnels I have the following applications allowed so they are not blocked. I also whitelist the source/destination IP's for my site to site vpns for added protection:
Hope that helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!