Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing through an IPSec VPN

Hi,

First of all, I tried to find existing discussions about the issue i'm facing but i'm not 100% sure I've searched/used the right keywords.

Let me explain:

I have 3 sites (let's call those SS, RR and DC).

SS subnet is: 172.42.23.0/24

RR subnet is:172.42.21.0/24

DC subnet is: 10.120.84.144/28

I have a site to siteVPN between SS and RR, which works fine, and another one between RR and DC, which also works fine for now.

Each VPN has the 2 endpoints subnets added to local/remote subnets, as it should. 

I want to allow traffic from SS to access DC, through RR. I dont want to mount another VPN from SS to DC, as the DC router is not mine and I cannot manage it directly..

I've asked our IT contact to allow the SS subnet to the "authorized/advertised" subnets on the DC config, which was done, and i've also added it on my side, on the RR DC config.

Despite that, this is not working and i'm stuck at the moment. 

The SS XG230 can ping my RR XG230, my RR router can ping the remote endpoint, but the SS XG230 cannot trace route, nor ping the DC endpoint.

Could you please assist? 

Thanks !



This thread was automatically locked due to age.