- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Site to Site VPN issue on 770 Appliance
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Site VPN issue on 770 Appliance
Hi All,
We have configured a Site to Site VPN on our 770 appliance with one of our partners, and everything works fine.
However their is an issue accessing a web site which resolves to the same public IP as the VPN tunnel. For some reason the CP is sending the traffic to the VPN tunnel and not out the internet.
Has anyone faced this before? or any ideas?
Thanks,
Kevin
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can exclude the peers routable IP from Enc Domain, that is, let all connections from internal networks to the public IP go thru Internet, see sk86582: Excluding subnets in encryption domain from accessing a specific VPN community, then this traffic will go thru internet. Strange, but possible...
Please refer to Locally managed SMBs and .def files for implementation !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A public routable IP can exist only once, so there is something very fishy going on here and i must not comment...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @G_W_Albrecht ,
Sorry if my question / description of the issue was not clear.
The web site that cannot be accessed is also hosted by the same partner that we have the Site-to-Site terminating on.
(So the Tunnel IP is the same for the URL - they have got some kind of portforward set up on their end)
Unfortunately they cannot/will not let us access the URL via the private IP.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can exclude the peers routable IP from Enc Domain, that is, let all connections from internal networks to the public IP go thru Internet, see sk86582: Excluding subnets in encryption domain from accessing a specific VPN community, then this traffic will go thru internet. Strange, but possible...
Please refer to Locally managed SMBs and .def files for implementation !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
