Forum Discussion
Site to site ipsec vpn pass through Link Controller
Hi Leonardo,
I recently have met the similar situation, here is the info: user -- checkpoint -- LC-- Internet -- checkpoint -- Other site users I have created the VS with destination VPN public IP、pool CP private IP with all protocol; VS with outbound 0.0.0.0、pool pool_gateway with all protocol. Through wireshark, phase I has been established, however there were no phase II packets. From CP, we always see the error that the pre-share-key mismatch even the key is so the same. CP TAC suggest that we deleted all VS and just created a NAT on NAT list in LC, that can work. However we just want to use VS to narrow down the public IP with related port in order to avoid attack, so any suggestion? thx in advance
SNAT default setting is to allow only TCP and UDP. Check the setting in System -> Configuration -> Local Traffic -> SNAT Packet Forwarding.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
