Dear All,
I need your advise/critiques for the procedure below.
Currently we have Branch connected to HO via IPWAN.
The plan is to move the branch to the Internet + VPN to HO.
Version: 80.10
Branch FW: 3100
HO has management server and central FW.
Procedure:
Assign External IP to the different branch FW interface.
Update topology on the Management server.
Create temp rules permitting communication between Management server and the branch *(with the new IP).
Create VPN community; Add HO and Branch FW there.
Apply policy to central and branch FW.
Change the static route for the branch FW to point to the new IP.
Change IP address for the branch object on Management server.
Re-attach the licenses.
Push policy to Branch firewall.
Create vpn tunnel interfaces on HO and Branch firewall.
Create static routes to internal subnets pointing to vpn interfaces.
Verify the traffic
Please let me know if I am missing anything here.
Kind regards,
Paul Z