Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN: Remote computers cannot access computers in the main office

Hi,

 

We setup an IPSec Site-to-Site VPN connection between our main office and branch office.

In the main office, we have two ISPs, each with its own router. First router has a local IP of 192.168.0.20 and the second router's (XG 230, actually) local IP is 192.168.0.2.

The branch office's router's (XG 135) local IP is 192.168.2.1. The VPN connects without any problem and computers from the branch office can successfully access computers/servers in the main office. For example, 192.168.2.60 can communicate with 192.168.0.50

Now, here's the problem. If the computer in the main office changes its default gateway to 192.168.0.20, the computers in the branch office will not be able to connect to it.


192.168.2.60 cannot access or even ping 192.168.0.52 and 192.168.0.53

192.168.0.52 and 192.168.0.53 can ping and access 192.168.2.60 due to static route configured on the first router

 

What do I need to do to make the computers in the main office still accessible through VPN even if I change their gateways to 192.168.0.20?

 

 

 

 

Thank you.



This thread was automatically locked due to age.
Parents
  • Access,

    You have an asymmetric routing problem so XG will block this traffic unless you beige the XG LAN port with the port that connects to the other router or disable the firewall for that network on XG using console:

    See this thread

    Thanks

Reply
  • Access,

    You have an asymmetric routing problem so XG will block this traffic unless you beige the XG LAN port with the port that connects to the other router or disable the firewall for that network on XG using console:

    See this thread

    Thanks

Children