[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Juniper routing through VPN tunnel

Posted on 2011-09-27
3
Medium Priority
?
463 Views
Last Modified: 2012-05-12
Hi!
I got 3 different WAN locations that need to speak to each other. Now they are connected through one IPSEC VPN and one IP-VPN (delivered by the ISP).   Location A and B, and B and C can talk to each other, but how can I route traffic so that also location A can communicate with location C?
I tried to add different routes on the location A firewall. But no matter what I do I can’t get the traffic through the IPSEC tunnel and forward to location C.
How can I solve this?
   VPN
0
Comment
Question by:elit2007
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 2000 total points
ID: 36709397
i have a hub - spoke VPN setup like this. At the spokes in order to route through the hub to another spoke i needed routes such as the following. Notice the route statement that have to go more than one hop have a destination IP of 0.0.0.0/0 as long as the ns5gt has policies to allow traffic, the routes will work

Site A
192.168.100.0/24 --> tunnel.1 dest-ip=192.168.100.1
192.168.120.0/24 --> tunnel.1 dest-ip=0.0.0.0      

Site B
192.168.150.0/24 --> tunnel.1 dest-ip =192.168.150.1
192.168.120.0/24 --> SiteC interface. dest-ip = 192.168.120.1

Site C
192.168.150.0/24 --> SiteB interface, dest-ip = 0.0.0.0
192.168.100.0/24 --> SiteB interface, dest-ip = 192.168.100.1
0
 
LVL 1

Author Comment

by:elit2007
ID: 36709453
In the meanwhile I have also figured out that the problem is the missing route on Site C.
Today nothing tells where 192.168.150.0 is located I the site C router.
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 36710325
Since site C may not be a juniper, you may have to point the route to the same gateway as Site B. Te ne5gt upon recieving the traffic will find the route to site A in its route table and send it to the correct place.
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question