- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Remote Access VPN Interface selection
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remote Access VPN Interface selection
Hi all,
I have two GWs in Cluster.
Here are its external interfaces:
1. Internet - with white IP 8.8.8.8 (for example purposes);
2. Private network - with IP 10.10.10.10 (for example purposes).
At the moment the 2nd network's topology setted up as Internal. When I change topology to External, remote users starts connect to those External interfaces with private addresses.
VPN clients connect to domain myvpn.mydomain.com - its IP adress is 8.8.8.8, and client application CP Endpoint Security shows:
Site: myvpn.mydomain.com
IP Address: 10.10.10.10 (instead of 8.8.8.8)
And fails to connect to that private address.
IP Selection by Remote Peer setted up as Calculate IP based on topology.
Can anyone help with that?
Thanks in advance.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@nemezis_rock You can configure link selection for remote access independent from site2site VPN via sk32229 - Configuring VPN Link Selection for Remote Access client
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why would you set topology to external if it is not external and not facing the internet?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Because it is actually an External network - L2 VPN. It is not local network but network between group of organizations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you try to use "link selection" here:
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will this affect on all IPSec tunnels or only for RA VPN users?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have some IPSec tunnels in that private external network. And also have Remote access community for VPN from internet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, so be careful.
What is set here?
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IP Selection by Remote Peer setted up as Calculate IP based on topology.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Better open SR# with CP TAC for this configuration !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@nemezis_rock You can configure link selection for remote access independent from site2site VPN via sk32229 - Configuring VPN Link Selection for Remote Access client
