Hello CheckMates,
I am facing some doubts with s2s vpn's, hoping you can help. Escenario:
- Cluster A, 3200 appliances R80.40 JHA Take 94 centrally managed.
- Cluster B, 5400 appliances R80.40 JHA Take 94 centrally managed (same management).
- Many remote SMB 1430 appliances R77.20.87 locally manged.
Cluster A has a s2s vpn with every SMB gateway, all 1430 gateways has the option "Route all traffic through this site" so branches use the vpn to access internal resources and Internet. In this case, cluster A has an empty encryption domain, and the community is configured to "one tunnel per gateway pair". With this configuration the traffic is working ok, traffic is correctly encrypted/decrypted in both ways.
Now we are trying to replicate the scenario with Cluster B and new branches with SMB 1430 too. the difference is that Cluster B has a encryption domain populated with many objects. We tried to use EDPC (encryption domain per community) and used an empty group object for that specific community. The vpn is up and cluster B can ping to the branch, the problem is that traffic originated from networks behind cluster B is not encrypted. We checked the remote encryption domain is not included in any other community/ED. We are not using VTI's in any vpn, only domain based.
So the doubts are: Is it supported to work with empty encryption domains in domain based s2s vpn's? if so, is it also supported using EDPC? Any idea/recommendation to face the scenario with cluster B? Thanks in advance.
Regards