Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Configuring Route based VPN on 2 site but failed to access server on the same subnet

$
0
0

Hi,

 

If NAT-ing did not resolve the problem, more likely it is not a routing issue on the server LAN.

 

Does Site-A have the necessary policies to allow this traffic?

If the config looks good, you can collect a simple debug on Site-A FW:

 

undebug all

clear db (will clear the exisiting debug data)

set ff src-ip <bgroup ip of the Site-B firewall> dst-ip <ip of the server>

set ff src-ip <ip of the serverdst-ip <bgroup ip of the Site-B firewall>

debug flow basic

<<ping server from siteB FW bgroup>>

<<Press Esc once it fails>>

get db st

 

The log printed by the last command will give an idea about traffic processing


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>