Solved

Juniper routing through VPN tunnel

Posted on 2011-09-27
3
404 Views
Last Modified: 2012-05-12
Hi!
I got 3 different WAN locations that need to speak to each other. Now they are connected through one IPSEC VPN and one IP-VPN (delivered by the ISP).   Location A and B, and B and C can talk to each other, but how can I route traffic so that also location A can communicate with location C?
I tried to add different routes on the location A firewall. But no matter what I do I can’t get the traffic through the IPSEC tunnel and forward to location C.
How can I solve this?
   VPN
0
Comment
Question by:elit2007
  • 2
3 Comments
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 500 total points
Comment Utility
i have a hub - spoke VPN setup like this. At the spokes in order to route through the hub to another spoke i needed routes such as the following. Notice the route statement that have to go more than one hop have a destination IP of 0.0.0.0/0 as long as the ns5gt has policies to allow traffic, the routes will work

Site A
192.168.100.0/24 --> tunnel.1 dest-ip=192.168.100.1
192.168.120.0/24 --> tunnel.1 dest-ip=0.0.0.0      

Site B
192.168.150.0/24 --> tunnel.1 dest-ip =192.168.150.1
192.168.120.0/24 --> SiteC interface. dest-ip = 192.168.120.1

Site C
192.168.150.0/24 --> SiteB interface, dest-ip = 0.0.0.0
192.168.100.0/24 --> SiteB interface, dest-ip = 192.168.100.1
0
 
LVL 1

Author Comment

by:elit2007
Comment Utility
In the meanwhile I have also figured out that the problem is the missing route on Site C.
Today nothing tells where 192.168.150.0 is located I the site C router.
0
 
LVL 18

Expert Comment

by:Sanga Collins
Comment Utility
Since site C may not be a juniper, you may have to point the route to the same gateway as Site B. Te ne5gt upon recieving the traffic will find the route to site A in its route table and send it to the correct place.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
ACL per VPN User 12 100
ACLs per VPN User 12 77
Sonicwall Web User login Redirect 9 32
Firewall port opening 2 17
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now