Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CheckPointerXL
Advisor

IKE IDs is smaller than Encryption Domain definition

Hi all,

very small setup:

S2S VPN Domain based, my enc domain has only 10.10.0.0/16,

Anyway, what i found by vpn tu is that my ike id is 10.10.0.0/17.

Trying to connect to a host inside 10.10.128.0/17, I get a new IKE id with a /32 on my side, this is related to the host IP of course.

I checked all my communities, but it seems that this behavior is not linked to sk170857.

So, why this happens?

Maybe some NAT rule inside 10.10.128.0/17 is breaking the subnet because of the natted IP which is not in peer's enc domain?

 

thanks a lot

 
0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events