- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi,
I'm deploying new a Maestro setup. I have it configured in tandem with our existing 3200 A/S cluster. The IP addressing is identical - on the Maestro interfaces I'm using an available IP address in the subnet as the interface address i.e. 254. I want set up a few IPSEC VPNs to remote peers to test connectivity. The existing 3200 has active IPSEC VPNs to these peers. Upon cutover, the new Maestro will assume the VPN domain on the 3200 cluster. In the interim for Maestro testing, I was considering creating a dummy network object using an available network to use as the VPN domain for the new Maestro (SMO) gw object, and NAT the outbound internal host traffic to this network. My concern is that the order of operations when packet arrives at interface will not allow this to work i.e. the natted traffic will not be considered interesting traffic so will not initiate phase 1 negotiation.
Regards,
Simon
Why cannot you use the same VPN domain for "old" setup and SMO? I think that is what you are aiming for, right?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
21 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY