Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Site to SIte Policy Base VPN Tunnel limit to one tunnel session

$
0
0

Hello ,

 

There are some points to consider here :-

 

1. Just by having another device with same config, you cannot cause intrusion. Inbetween routers will play a major part on how they are routing the traffic destined to FWA unless IP packets are duplicated somewhere between and forwarded to both FWA and FW C

2. Both FWA and FWC will not have simultanoeus VPN up with FWB. FWB will have VPN with only one of them.  Again routing will play a role here.

3. Even after VPN is up, the ESP traffic has its own mechanism of SPI values and sequence numbers. If FWC does manage to send soem traffic to FWB, the chances are FW B will reject those packets as BAD SPI or out of sequence packets. if replay protection is enabled on FWB

 

Regards

Vatsa


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>