Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
GA
Explorer

S2S with PPPoE

I welcome colleagues.
Please help with a solution. I am building a vpn tunnel with a remote gateway 1530, which is connected by the same management server.
The WAN external interface works via PPPoE using the provider's login and password, receiving a dynamic address.
In the settings of the smart console, I set up a dynamic address on the WAN interface, in the Link Selection I configure setting resolve by dns name, but the traffic does not enter the tunnel. I renew the vpn certificate by adding alternative names to it, the situation did not help.
By setting a static address, I get the error: Main Mode local machine configured not to respond to unknown IP addresses (i.e. not exportable for SR, and/or not included in the RemoteAccess community, and/or no DAIP's defined).
How should the tunnel be built in this case? What exactly to do in Link Selection?

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

Please provide more details - we know one peer is a 1530 (firmware version ?) with DAIP managed by a CP SMS (version / jumbo take ?), but you give no details of the peer !

Please look into sk117713: "Main Mode local machine configured not to respond to unknown IP addresses" error on local... and sk167473: Dynamically Assigned IP Address (DAIP) Gateway FAQ

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
GA
Explorer

Hi Albrecht.
Thanks for your reply.
SMB version 80.20.35, I don't remember the exact build.
Management server 81.10 latest take. I have seen these articles and none of them helped.
I've tried using just the domain name, fqdn, as written there, but that doesn't help. Tunnel traffic is sent to the Internet.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

80.20.35 is rather old, current version is R80.20.50. Still you do not mention the peer ! The SMB GW using DAIP has to start the VPN tunnel - sometimes, NAT-T has to be activated manually. see sk162472.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
GA
Explorer

Peer 81.10 last take.
And where does traversal nat come in if both peers are connected directly to the provider?

0 Kudos
G_W_Albrecht
Legend Legend
Legend

It does only come in if the VPN fails ! Better contact TAC to get this resolved quickly...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events