Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
nemezis_rock
Contributor
Jump to solution

Remote Access VPN Interface selection

Hi all,

I have two GWs in Cluster.

Here are its external interfaces:
1. Internet - with white IP 8.8.8.8 (for example purposes);
2. Private network - with IP 10.10.10.10 (for example purposes).

At the moment the 2nd network's topology setted up as Internal. When I change topology to External, remote users starts connect to those External interfaces with private addresses.

VPN clients connect to domain myvpn.mydomain.com - its IP adress is 8.8.8.8, and client application CP Endpoint Security shows:

Site: myvpn.mydomain.com
IP Address: 10.10.10.10 (instead of 8.8.8.8)
And fails to connect to that private address.

IP Selection by Remote Peer setted up as Calculate IP based on topology.

Can anyone help with that?
Thanks in advance.

0 Kudos
1 Solution

Accepted Solutions
Wolfgang
Authority
Authority

@nemezis_rock You can configure link selection for remote access independent from site2site VPN via sk32229 - Configuring VPN Link Selection for Remote Access client

View solution in original post

9 Replies
G_W_Albrecht
Legend Legend
Legend

Why would you set topology to external if it is not external and not facing the internet?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
nemezis_rock
Contributor

Because it is actually an External network - L2 VPN. It is not local network but network between group of organizations.

0 Kudos
AkosBakos
Advisor
Advisor

Have you try to use "link selection" here:

link.png

----------------
\m/_(>_<)_\m/
0 Kudos
nemezis_rock
Contributor

Will this affect on all IPSec tunnels or only for RA VPN users?

0 Kudos
nemezis_rock
Contributor

I have some IPSec tunnels in that private external network. And also have Remote access community for VPN from internet.

0 Kudos
AkosBakos
Advisor
Advisor

Yes, so be careful.

What is set here?

----------------
\m/_(>_<)_\m/
0 Kudos
nemezis_rock
Contributor

IP Selection by Remote Peer setted up as Calculate IP based on topology.

 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Better open SR# with CP TAC for this configuration !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Wolfgang
Authority
Authority

@nemezis_rock You can configure link selection for remote access independent from site2site VPN via sk32229 - Configuring VPN Link Selection for Remote Access client

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events