Forum Discussion

destevez54_3221's avatar
destevez54_3221
Icon for Nimbostratus rankNimbostratus
May 26, 2017

One way traffic through ipsec tunnel

I'm working on setting up an vpn tunnel between two VIPRION clusters in different sites. They are running 12.1.2 HF1. I've got multiple subnets to protect within the VPN and have successfully gotten an IPv4 VPN up and running from 192.168.1.0/24 to 192.168.2.0/24.

 

My problem is specific to another IPv6 traffic selector. If I initiate traffic from one side to the other, I can see the ESP packets and the native traffic arrive on the remote node, but no response traffic is sent.

 

To troubleshoot the issue, I've attempted to create a route using the local node external IP and receive the error that the gateway can't be the same as a self IP. Likewise, using the remote node external IP results in the "not directly connected" error. If I'm trying to route traffic from 2000:1000:1000:1:800::/69 to 2000:1000:3000:1:800::/69, which gateway should I be using? VLAN/IP address? The IPv6 traffic is not routed beyond the node.

 

No RepliesBe the first to reply