Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
AaronCP
Advisor

Hey @the_rock,

 

I will need to check my company policy on a remote session and get back to you - but thanks for the kind offer!

 

It is supposed to be a permanent tunnel, but this is where we encounter the error. Disable permanent tunnel and it presents the correct traffic selectors and the traffic works fine. Enable permanent tunnels and the public IP of both gateways are presented as the traffic selectors (these are not specified in the encryption domains, btw) and phase 2 fails and traffic does not pass through the tunnel.

 

I did set up a VTI between both gateways, but this did not help. I also added a static route for the traffic to the VTI and that didn't help, either.

(1)
Who rated this post