Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN to VPN rules

Hi all,

Given the state of the world, I'm trying to make some firewall changes to our setup, and I'm hoping someone can give me a bit of a steer.


We have a pair of IPSec VPN's running to Azure (which works fine)

We have a Remote SSL VPN for staff to dial into the office (which works fine)

What I'm trying to get working is an interlink between the two VPN configs so that staff can dial in from home, and then get to our Azure.

 

I've added the remote subnet to the IPsec ranges, and I'd thought it might be as simple as making a VPN<>VPN rule like so:

No dice though. If anyone could provide some insight as to how to diagnose where my config is failing me?



This thread was automatically locked due to age.
Parents
  • Turns out my rules were in fact fine. The issue lay with how SFOS 17.5 works with Azure VPN's. The subnets don't work until there is some communication from the remote (Azure) end.

    Running a ping from the remote end always fails the first (and usually) second time - but third time round it will get to the destination.

    I'm told that SFOS 18 and the upcoming 18.1 resolve this problem.

    In the meantime I've got a scheduled task running a ping job every 15 minutes to both subnets (the local on-prem and the local remote SSL) and it's working fine.

Reply
  • Turns out my rules were in fact fine. The issue lay with how SFOS 17.5 works with Azure VPN's. The subnets don't work until there is some communication from the remote (Azure) end.

    Running a ping from the remote end always fails the first (and usually) second time - but third time round it will get to the destination.

    I'm told that SFOS 18 and the upcoming 18.1 resolve this problem.

    In the meantime I've got a scheduled task running a ping job every 15 minutes to both subnets (the local on-prem and the local remote SSL) and it's working fine.

Children
No Data