Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FtW64
Participant

Remote gateway (cluster) over the Internet

Consider a local management- and log server (SMS) and a gateway (cluster) on location A.

What is best practice to setup a remote gateway (cluster) on location B,  under control of the SMS on location A.

Locations A and B are connected over the Internet.

My first thought is to setup a site-to-site IPSec VPN between the two sites and have the management traffic passing the VPN.

However, if the VPN fails (e.g., due to an incorrect policy installation), we also loose the management connection to location B. And there is no (easy) way to install the proper policy to get the VPN working again.

Should we keep the traffic between the SMS and location B outside (independent of) the VPN connection?

If so, I remember you must make quite a few exceptions (including manual editing of *.def files on the management server) to keep the SMS traffic outside the VPN…

-Frank

 

0 Kudos
6 Replies
the_rock
Legend
Legend

I would say VPN would make sense onbiously, but then as you said, if it fails, you wont be able to communicate. Do you have simple diagram you can send, just to make sure Im not missing anything here.

Best,

Andy

0 Kudos
FtW64
Participant

Hi Andy,

Old school pen-and-paper 😀:

2024-02-13 15_11_40-WhatsApp — Mozilla Firefox.jpg

-Frank

0 Kudos
the_rock
Legend
Legend

Hey, its the BEST 😉

K, I think I have better picture now with what you sent. So yes, you can keep the connection between SMS and gw B separate, but Im thinking what would be best way to do this apart from VPN tunnel...

Andy

0 Kudos
FtW64
Participant

Hi Andy,

I remember it is quite a hassle (lots of special settings and even editing some .def files on the SMS) to keep only traffic between SMS and the remote gateway (B) outside of the encrypted traffic...

-Frank

0 Kudos
the_rock
Legend
Legend

It is and truth be told, I always sucked at it lol

Personally, I would not change it myself, unless you are 100% sure what needs to be done. Probably better to verify with TAC.

Best,

Andy

0 Kudos
FtW64
Participant

Hi Andy,

I'm afraid TAC will not answer these questions: "did this work before", "NO", "then please go to professional services"...

Thanks for your help anyway. I guess it boils down to fiddling with crypt.def after all :-).

Frank

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events