Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nik_Bloemers
Collaborator

Route-based VPN Proxy ID 0.0.0.0/0?

Jump to solution

Hi CheckMates,

Am I correct in understanding that for route-based VPN with unnumbered interfaces the only available option is universal tunnel, so proxy ID of 0.0.0.0/0?

If not, can anyone tell me how you're supposed to get the proxy ID right?
Kind regards,

Nik Bloemers

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

Correct, a route-based VPN tunnel has to be universal since we do not know ahead of time what traffic IP routing will dump into the VPN tunnel; set one tunnel per gateway pair in the VPN Community object to get 0.0.0.0/0's.  With a domain-based VPN we do know exactly what IP addresses will appear in the tunnel based on the static VPN domain definitions.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

1 Reply
Timothy_Hall
Champion
Champion

Correct, a route-based VPN tunnel has to be universal since we do not know ahead of time what traffic IP routing will dump into the VPN tunnel; set one tunnel per gateway pair in the VPN Community object to get 0.0.0.0/0's.  With a domain-based VPN we do know exactly what IP addresses will appear in the tunnel based on the static VPN domain definitions.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post