Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
an_technical
Explorer

SMS and VSX gateway communication over ipsec tunnel

Hi All,

 

I am working on a deployment where SMS and VSX gateway are separated by cities and communication is over ipsec tunnel.

I commented #define ENABLE_CPD_AMON from implied_rules.def rule and created new rule in access policy to send traffic in vpn.

Will this be enough for management server to communicate with VSX gateway (connectivity from mgmt to VSX, Policy installation etc)

 

Thanks

0 Kudos
2 Replies
an_technical
Explorer

By commenting #define ENABLE_CPD_AMON MGMT server was able to reach VSX gateway and install policy but I cannot create new interface or virtual system. I see 18191 port traffic is going as clear text. I tried to exclude #define ENABLE_CPD but it doesn't work and now policy push is failing on virtual system with TCP connectivity failure (Port 18191)

In other gateway I see traffic is dropping saying, clear text should be encrypted. 

VSX should send it in through ipsec tunnel.

 

0 Kudos
PhoneBoy
Admin
Admin

In general, we do not recommend making this configuration change as you can end up in a situation where you are unable to manage your gateways due to a VPN outage.
Also, it's best to consult with TAC to ensure you are making the correct changes to implied rules.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events