1
General Discussion / Re: IPSEC TUNNEL and REMOTE 1:1 NAT
« on: December 03, 2018, 09:01:19 pm »
Hello,
Thanks for your answers.
@mimugmail : Yes it is my configuration type.
I try with this configuration, but It does not works:
VPN is UP
On remote site, i have take SDP to my local network, ie: 192.168.0.0/24,
Phase2 Remote 192.168.2.0 local 10.75.10.1
I take 1:1 rule: IPsec 10.75.10.1/24 192.168.0.1/24 *
I have allowed all traffic in LAN, IPSEC interfaces.
When I ping a machine (10.75.15.18) from local site my remote site I see ping arrived in remote machine (but I don't have response):
Ping: src: 192.168.2.94 dst: 192.168.0.18
And If I ping in my remote machine the local machine (ping 192.168.2.94), it's failed too.
I think I have a problem with routes for the back route.
What is wrong ? Maybe I do add a static route ?
@bartjsmit: Nothing happens if I create NAT rules, I even get an error on which tells me that ip does not exist? Do I have to create a "LAN" network interface in order to assign NAT rules to it? A virtual ip? In this case I dont use SDP ?
Thanks for you help,
Regards,
Ben
Thanks for your answers.
@mimugmail : Yes it is my configuration type.
I try with this configuration, but It does not works:
VPN is UP
On remote site, i have take SDP to my local network, ie: 192.168.0.0/24,
Phase2 Remote 192.168.2.0 local 10.75.10.1
I take 1:1 rule: IPsec 10.75.10.1/24 192.168.0.1/24 *
I have allowed all traffic in LAN, IPSEC interfaces.
When I ping a machine (10.75.15.18) from local site my remote site I see ping arrived in remote machine (but I don't have response):
Ping: src: 192.168.2.94 dst: 192.168.0.18
And If I ping in my remote machine the local machine (ping 192.168.2.94), it's failed too.
I think I have a problem with routes for the back route.
What is wrong ? Maybe I do add a static route ?
@bartjsmit: Nothing happens if I create NAT rules, I even get an error on which tells me that ip does not exist? Do I have to create a "LAN" network interface in order to assign NAT rules to it? A virtual ip? In this case I dont use SDP ?
Thanks for you help,
Regards,
Ben