Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Site-to-site VPN between 3 locations (hairpin NAT)

$
0
0

I'm not sure I follow the topology now.  Are you saying there are two paths between spoke a and the data center hub site?

If so, asymmetrical routing could cause failures.

 

Since this does work in one direction this tends to validate the routing and point to a policy in the non-working direction blocking traffic.

On the SSG policy log view there is column for counts on the policy in both directions "bytes sent" and "bytes recieved".  this is where I was suggesting to look.  Trying to see a policy where only one direction is counting for the non-working direction.  Meaning the traffic comes in one direction only.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>