Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
yumin_hu
Participant
Jump to solution

IPSec VPN encryption domain problem (Star community)

I would like to ask experts a question about the scope of the VPN encryption domain definition.
If a branch of a company needs to access the company data center through IPSec VPN, the encryption domains at both ends are defined as: branch = 10.1.5.0/24, company data center = 10.0.0.0/8
If the encryption domain is defined as such, will there be any problem with IPSec VPN communication?Smiley Embarassed

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin
Encryption domains cannot overlap in this manner. Not to mention, you'll have routing issues. The branch side will need to be NATTED to talk to the datacenter side and the datacenter side will need to refer to the branch side by the NATted IPs.

View solution in original post

2 Replies
PhoneBoy
Admin
Admin
Encryption domains cannot overlap in this manner. Not to mention, you'll have routing issues. The branch side will need to be NATTED to talk to the datacenter side and the datacenter side will need to refer to the branch side by the NATted IPs.
yumin_hu
Participant
I probably understand what you mean, In other words, when defining the scope of the encryption domain, the encryption domain of the data center end and the branch end cannot be an inclusion relationship, and must be an independent network segment.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events