cancel
Showing results for 
Search instead for 
Did you mean: 

Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

j_friedrich_
New Contributor

Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

Hi guys,

We are wondering if we can VPN ALL traffic from one 5GT to another 5GT through the VPN. That includes web surfing, email's, you name it. We have connected 5GT's for VPN before, but, not in this manner. We don't want ANY traffic to go out of the local 5GT, but, want it to go through the other VPN 5GT end.

Any suggestions?

Thanks for everyone's time!

Jason

4 REPLIES 4
Raheel_
Occasional Contributor

Re: Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

j_friedrich_
New Contributor

Re: Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

Hi, Thanks for the response. So, we have configured the route based VPN connection, but, as shown in the example, the routing will only pass traffic that is referencing the other subnet. Can you give us an example of a routing setup that passes ALL traffic thru the other VPN end? Simple put, the traffic is routed thru the other VPN end subnet, regardless of the traffic. Thanks. Jason
Raheel_
Occasional Contributor

Re: Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

you have to define a static route. please draw your topology.

thanks

raheel

j_friedrich_
New Contributor

Re: Newbie question...Can we VPN ALL traffic from 2 connected 5GT's?

Hi,

We have tried to follow the instructions from this article-KB7994 and have not had any luck in getting it to work. Here is a breakdown of our network:


1. We have followed article KB4178 for connecting 2 NS5GT's and it's working fine.
2. Our local (hub) NS5GT has an internet GW address of 96.51.216.1 to the upstream ISP. The local subnet is 192.168.10.0/24
3. Our remote (spoke) NS5GT has an internet GW address of 75.159.160.1 to the upstream ISP. The local subnet is 192.168.9.0/24.
4. On the hub site, we have put in the following policy:
'set policy from trust to untrust 192.168.9.0/24 Any Any nat src permit'
5. We have setup on the remote (spoke) NS5GT under 'routing - destination' - 'set route 0.0.0.0/0 interface tunnel.1'


Where do we put in the remaining static route in the remote (spoke) NS5GT to complete the routing to force traffic through the local (hub)?
We have tried different variations and the internet traffic on the remote (spoke) is not going through the local (hub). It's still going out through the local ISP.


Any suggestions?

Thanks.

Jason