Forum Discussion
faycal_29095
Nimbostratus
Dec 02, 2007Virutal Server for VPN
hi everybody;
i create a Virtual server, type standard (0.0.0./0) for VPN use (UDP 500).
but i see only some packet in this VS.
please, can you help me to understand where exactly can w...
JRahm
Admin
Dec 04, 2007I would do this by applying a virtual 0.0.0.0/0 against ONLY the internal vlan, with a rule applied (below). I am not sure I understand your requirements as a couple of them seem conflicting. Here's a start for you, and If I am misunderstanding, please post back. Also, if you use AH or NAT-T at all, you'll also need to allow for protocol 51 and udp/4500 (respectively)
when CLIENT_ACCEPTED {
if { [IP::protocol] == 50 } {
pool isp-gateways member ISP1
} elseif { [UDP::local_port] == 500 } {
pool isp-gateways member ISP1
} else {
pool isp-gateways
}
}Of course, you'd need to make sure you have a forwarder for your internal vlan as well applied ONLY to the public-facing vlan.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects