Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Dial-up VPN to SSG-350 (site to site VPN)

$
0
0

I still don't see any packet for the ip 192.168.99.109.It's probably because of the policy.  I understand that your are using policy id 19 for this tunnel, right?

 

set policy id 19 from "Untrust" to "Trust" "Dial-Up VPN - Staff" "DXB_Office" "ANY" tunnel vpn "Dialup VPN - Staff" id 0x30 log

 

Where:

set address "Trust" "DXB_Office" 192.168.135.0 255.255.255.0

 

 

If there is no spesific reasons then why policy has only 192.168.135.0/24 rather it should have 192.168.135.0/16, right? Can you please rectify the policy, renogitaite the client VPN, and take the debug again with the PING to whether packets is seen now ot not . Actually, i am expecting IPsec client to get a dissferent proxy id for this time for the IP 192.168.135.0/16 .

 

Thanks,

Vikas

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles