Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
This widget could not be displayed.
2 Replies

Hello everyone!

In the scenario where we have SASE using the Wireguard connector, we have observed that the connection IP for accessing applications is not from the SASE client but from the connect, that is, the connection is NATed. The question is, how can we make the user connection arrive with the connection IP in the application? Reason: in this scenario, security control in the applications is done by connection IP.

Below is the current scenario.

SASE client network: 10.17.4.0/22
On-premise client network: 10.0.250.0/23, 172.16.0.0/12 and 192.168.0.0/16

In the scenario where I use the IPSec VPN connector, would it be possible to meet this requirement?

 

Thank you!

[SASE] connection NATed

[SASE] connection NATed

Hello everyone!

In the scenario where we have SASE using the Wireguard connector, we have observed that the connection IP for accessing applications is not from the SASE client but from the connect, that is, the connection is NATed. The question is, how can we make the user connection arrive with the connection IP in the application? Reason: in this scenario, security control in the applications is done by connection IP.

Below is the current scenario.

SASE client network: 10.17.4.0/22
On-premise client network: 10.0.250.0/23, 172.16.0.0/12 and 192.168.0.0/16

In the scenario where I use the IPSec VPN connector, would it be possible to meet this requirement?

 

Thank you!

Hello everyone!

In the scenario where we have SASE using the Wireguard connector, we have observed that the connection IP for accessing applications is not from the SASE client but from the connect, that is, the connection is NATed. The question is, how can we make the user connection arrive with the connection IP in the application? Reason: in this scenario, security control in the applications is done by connection IP.

Below is the current scenario.

SASE client network: 10.17.4.0/22
On-premise client network: 10.0.250.0/23, 172.16.0.0/12 and 192.168.0.0/16

In the scenario where I use the IPSec VPN connector, would it be possible to meet this requirement?

 

Thank you!

D_TK
Advisor
D_TK
Advisor

Yep, as phoneboy said, you're seeing the expected result.  We tried that method and found it to be untenable, so we just added ipsec tunnels to all on-prem gateway and now the actual client IP is exposed to the onprem app.  hth

Yep, as phoneboy said, you're seeing the expected result.  We tried that method and found it to be untenable, so we just added ipsec tunnels to all on-prem gateway and now the actual client IP is exposed to the onprem app.  hth