Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

XGS87 (SFOS 20.0.2 MR-2-Build378) VPN Routing Problem

Hello, 

we have a problem which with the routing over VPN. 

A user is connected to SSL VPN with the XGS. The XGS has a site to site IPsec VPN connection to resources in the cloud. A request from the user's client using SSL VPN for resources in the cloud network is not possible. I can access the resources in the cloud from the LAN. When I do a traceout from the client, I see how the SSL VPN gateway is addressed, but instead of going via the site to site VPN route, the packet is sent over the Internet.  If I do a traceroute to the cloud resource in the XGS, it also goes over the Internet. When I request the same resource via route resolution, the XGS shows me a direct connection.  But I can't create a route because I can't select an interface for the Site to Site VPn.




formated
[bearbeitet von: LuCar Toni um 3:58 PM (GMT -7) am 3 Sep 2024]
Parents
  • Likely you need something like a DNAT Rule or you can adjust the IPsec tunnel.

    The ipsec tunnel only routes the traffic matching the local and the remote network (in your case LAN and the Cloud resource). 

    You can adjust both sides of the tunnel and add the SSLVPN tunnel to it. This will work.

    If you cannot do this, you need to work with a SNAT and masq, which requires more adjustments. 

    __________________________________________________________________________________________________________________

Reply
  • Likely you need something like a DNAT Rule or you can adjust the IPsec tunnel.

    The ipsec tunnel only routes the traffic matching the local and the remote network (in your case LAN and the Cloud resource). 

    You can adjust both sides of the tunnel and add the SSLVPN tunnel to it. This will work.

    If you cannot do this, you need to work with a SNAT and masq, which requires more adjustments. 

    __________________________________________________________________________________________________________________

Children
No Data