Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Neville_Kuo
Advisor

在vpn domain裡排除特定subnet

各位如果在設定VPN時需要將某些IP或者subnet排除在vpn domain裡,可以試試以下這篇SK:

Excluding subnets in encryption domain from accessing a specific VPN community 

這招連Star架構的vpn routing設定成To center only都有效。

但是請注意crypt.def檔的位置,不同的管理主機搭配不同的gateway版本位置會不太一樣,在以下SK也有說明:

Location of 'crypt.def' files on Security Management Server 

比方說我們公司的客戶管理主機是R80.10,但gateway是R77.30,那crypt.def的位置就在"/opt/CPSFWR77CMP-R80/lib/"裡,改錯是無效的。

3 Replies
Danny_Yang
Ambassador
Ambassador

N大哩就故謀來啊

0 Kudos
Neville_Kuo
Advisor

沒辦法最近被人唸到快七孔流血

Danny_Yang
Ambassador
Ambassador

誰叫你最近都只潛水

0 Kudos
Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events