Hi!
I´m in the process of setting up a Site2Site VPN from our office to Cisco Umbrella to channel all user surf traffic to the Umbrella "Proxy".
Tunnel is a star community, one tunnel per gateway
My gateway is center and VPN domain is "User-computer-VLAN" (192.168.5.0/24).
Satellite Gateway is the Umbrella gateway with VPN domain "Internet_without_Private_Networks". This is a group-with-exclusion object, consisting of "Internet" except "Private networks (RFC 1918)". The purpose is that the clients shall access all internet IPs through the tunnel, only then being filtered through the Umbrella proxies.
The traffic is then allowed in the ruleset, I also added the community to the rule.
This works nicely but there is a side effect. Every traffic from the gateway itself is also send into the tunnel. This ranges from DNS traffic for ISP redundancy DNS proxy updates to user-VPN-tunnels not working to the gateway to not being able to download updates for IPS and patches.
"Excluded services" might help me with ISP redundancy ping and User-VPN-tunnels but not with the IPS updates. Eventually, Client DNS shall also go through the tunnel, so I can´t exlude that either.
Is there any way I can exclude the gateway from using the tunnel?
Any ideas appreciated!
Greetings,
Robin