Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Ambiguity in manual for SD-WAN policy destination

Manual notes the following, but WAN is not an option.

Check if an SD-WAN policy route has Destination networks set to Any.

Change the setting from Any to a specific choice (example: WAN) from the list. Setting it to Any forces XG Firewall to forward internal traffic also to the WAN interface.

 

This seems like a very easy solution to my problem of all VPN SSL traffic appearing to try routing out the WAN interface.

I am using OSPF routing for the network, and precedence is sd-wan. vpn, static, and I have no static routes.

Am I missing a workaround to the possible Any/Any issue?



This thread was automatically locked due to age.
Parents Reply
  • OpenVPN is limited to "It needs a Permitted Network". 

    If you select Tunnel All, this would not be needed.

    If you select Split Tunneling, you need to specify all Permitted Networks within your Network. You could work with /8 Networks

    __________________________________________________________________________________________________________________

Children