Hello CheckMates
I would like to request some clarification regarding the Star VPN Routing option "To center or through the center to other satellites, to Internet and other VPN targets" (3rd option). When I have the option enabled, it becomes possible for all Center Networks, even the ones not part of the Center-EncDom on the Center Gateway to reach all Satellite EncDom Networks. It will match the ACL and enter the VPN Tunnel, when to my current understanding it is not meant to. Could anyone please clarify as to why this is?
See a small summary of my configuration below, all devices are OpenServers running R81.20 with JHF 53.
Center Encryption Domain: 172.16.1.0/24
Satellite Encryption Domain: 192.168.1.0/24
Center Hosts
PC-A - 172.16.1.1 (part of Center-EncDom)
PC-C - 10.10.2.10
Satellite Host
PC-B - 192.168.1.1 (part of Satellite-EncDom)
Ping Result
PC-A -> PC-B reachable, enters VPN-Tunnel
PC-A -> PC-C reachable local site
PC-B -> PC-A reachable, enters VPN-Tunnel
PC-B -> PC-C unreachable
PC-C -> PC-A reachable local site
PC-C -> PC-B reachable, enters VPN-Tunnel (matches ACL, but does not match EncDom)
When enabling the 2nd option "To center and to other satellites through center", it works as I intend for it to work. Meaning that PC-C traffic towards PC-B no longer enters the VPN tunnel, gets accepted by the ACL rule and routed into the void. See a ghetto paint version for a topology below.
Thank you for any and all comments that would help me better understand the VPN product!