cancel
Showing results for 
Search instead for 
Did you mean: 

SSG5 AutoKey IKE - Allows Connection, but no access to Trust

gnweber_
New Contributor

SSG5 AutoKey IKE - Allows Connection, but no access to Trust

I have an SSG5 setup with an AutoKey IKE VPN. I can connect to the VPN, ping the gateway (10.0.1.1) in the Trust zone, and even get to the WebUI for manangement of the SSG5 over the VPN. I can also ssh to the SSG5 while on the VPN connection. However, I cannot get to anything else in the Trust zone. Any help would be greatly appreciated.

I have attached my config file for review.

gnweber

1 REPLY 1
gnweber_
New Contributor

Re: SSG5 AutoKey IKE - Allows Connection, but no access to Trust

I found the following post in the Firewalls area this morning, which fixed my problem. The gist is to do the following:

- Edit your VPN policy

- Go in advanced configuration

- Activate the source NAT with Egress Interface

This works, but the contributor of the information says its a workaround and that the underlying issue may be a routing problem. In site-to-site configs I've seen static routes for routing the the tunnel. Is that required/possible in a dialaup VPN? Or should I be satisfied with the directions above and just leave well enough alone?

I've attached my now working config...

gnweber