Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CEEJAY
Contributor

Hub and Spoke Policy Based VPN Spark Firewall

Hello, is there someone could help me with my issue on my VPN. I have two branch offices connected to the Head Office via Site to Site VPN. Branch 1 device (172.16.86.59) needs to telnet to Branch 2 (10.201.20.45). From branch 2 perspective, the source should be coming from HO local network using (172.16.20.133). I also created a SNAT in the Head Office Firewall. 

Branch 1 to HO: Local Network 172.16.86.0/24 | Remote Network: 172.16.20.0/24

HO to Branch 1 : Local Network 172.16.20.0/24 | Remote Network: 172.16.86.0/24
HO to Branch 2: Local Network 172.16.20.0/24 | Remote Network : 10.201.20.0/24 & 10.201.22.0/24

Branch 2 to HO: Local Network: 10.201.20.0/24 and 10.201.22.0/24 | Remote Network: 172.16.20.0/24

In my testing, I successfully telnet to 10.201.20.45 from Branch 1 172.16.86.59 after uncheking the "disable NAT" in VPN Settings for both site. But when telnet is successful. The web portal in the 10.201.22.0/24 is not accessible in the HO. 

Also the tunnel status has a warning sign, indicating that only Phase 1 is up. 

 
 

 

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events