When an Inbound SNAT is possible, I can translate the internet address to a local address of PhM1 and that would solve the problem.
It's not missing. You can define SNAT for inbound connections by creating an outbound NAT rule on the tunnel interface. Which makes sense if you visualise the flow of packets.
Quote from: Patrick M. Hausen on October 05, 2023, 12:25:19 amIt's not missing. You can define SNAT for inbound connections by creating an outbound NAT rule on the tunnel interface. Which makes sense if you visualise the flow of packets.Yes I thought of that. And I tried that. And it failed.As soon as I do that, I see in the live Log that it works, but no data is going through the tunnel anymore.I searched the forum for this, and found that SNAT is not working on a IPSEC interface / tunnel that uses routing.
Only use this setup if you only have route based VPN tunnels and don't plan on any policy based ones in the future.