Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Site-to-site VPN between 3 locations (hairpin NAT)

$
0
0

Hello,

 

The firewalls on both Branch sides have the routes, I agree. Based on your post earlier, I understand that the Branch firewall was forwarding the pings but workstation was not responding to the pings, which seems because the workstation will not be responding to any traffic other than those to which it has a route. 

 

NAT is not madatory for Hub and Spoke scenario. But when one Spoke side workstations/hosts dont know how to reach to other Spoke subnet, then a NAT is needed.

 

Thanks,

Pranita


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>