Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DR_74
Contributor

VPN to allow remote branch accessing Internet through central GW

Jump to solution

Hello,

We have the following setup:

2 R80.10 clusters managed by a R80.10 SmartCenter

A VPN is established between the 2 clusters

 

2019-04-05 10_38_44-Clipboard.png

The VPN community allows only VPN domains defined behind each Firewall.

How can we reconfigure it so that the remote branch can access the corporate LAN AND also be routed to the Internet through the Central FW?

Regards

0 Kudos
1 Solution

Accepted Solutions
G_W_Albrecht
Legend
Legend

1: Change VPN community to star topology

2. Set main GW to Center GW

3. Add peer as satellite GW

4. Enable VPN Routing with option To center, or through the center to other satellites, to internet and other VPN targets. Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.

 

CCSE CCTE SMB Specialist

View solution in original post

3 Replies
G_W_Albrecht
Legend
Legend

1: Change VPN community to star topology

2. Set main GW to Center GW

3. Add peer as satellite GW

4. Enable VPN Routing with option To center, or through the center to other satellites, to internet and other VPN targets. Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.

 

CCSE CCTE SMB Specialist

View solution in original post

Will_Hargreaves
Employee
Employee

Is it possible to ENFORCE remote access users to break out to the internet only through the VPN to their corporate LAN, and deny them internet access when they are not connected to the VPN? (except for allowing the minimum necessary internet access to establish the VPN).

0 Kudos
mdjmcnally
Advisor

Not sure why posted this onto this as surely a different question,

 

Whilst you can enable Hub Mode and enforce it so that when connected to the Remote Access VPN then forces you to go via the VPN, it won't block access to the Internet when not on the VPN.

 

Possibly with the Endpoint Suite and the Connected/Disconnected Policy then on the Disconnected Policy then could block access to the Internet and just access to the Gateway, and DNS, DHCP etc.   Make sure that HotSpot is enabled so can authenticate as well to Wifi if neccessary.

That way when out of the Office forces the Client to hookup the VPN to get anywhere

0 Kudos