Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Site-to-site VPN between 3 locations (hairpin NAT)

$
0
0

Want to connect the VPN between 3 sites like below

BranchA(SSG140) <-> HA(SSG140) <-> BranchB(Palo Alto PA-820)

The VPN between the branch and HA were establish. Problem is how to make Branch A and B communicate through HA.

Found a link from Cisco website which demonstrate this situation.

https://community.cisco.com/t5/security-documents/how-to-configure-site-to-site-vpn-with-hairpinning-on-cisco-asa/ta-p/3157388

It mention "hairpin NAT" which I never heard of it before. My existing VPN no need any NAT policy.

Is the "hairpin NAT" a necessary setting for this situation?


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>