[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 275
  • Last Modified:

site to site vpn ping

I created a VPN tunnel using ipsec between rras 2008 and a sonicwall.  tunnel comes up fine but i cant ping devices on either network.

i setup static routes as follows but it did not make a difference.

int:wan

dest: remote network

sm: /24

gw: remote ip of vpn gw

I am not sure if this is relevant but when i enable nat the tunnel doesnt come up.  Hopefully someone can point me in the right direction.  Thanks
0
Kylo Ren
Asked:
Kylo Ren
  • 3
  • 2
1 Solution
 
carlmdCommented:
As a part of the setup you would normally have to define what networks are accessible via the tunnel, at each end. Did you do anything like that?
0
 
Kylo RenSystem EngineerAuthor Commented:
yea definetly.  Before i installed the static routes i created a ip sec policy similar to the example below.

Local GW: Public IP
Local Subnet: 192.168.0.0/24
Remote GW: Public IP
Remote Subnet: 192.168.1.0/24

Tunnel appears to be fine (ike phase 1&2 SA's are visible) but no matter i can't route any traffic through it.
0
 
carlmdCommented:
If you have the option, I would change the subnet on one end from the 192.168.x.x to one of the other non routable ranges (10.0.x.x or 172.16.x.x.).
0
 
Kylo RenSystem EngineerAuthor Commented:
ok no furtunately i dont have that option so is there a work around? anything that i can test for to see where the issue lies?
0
 
carlmdCommented:
Try running a traceroute and see how far it gets.

Also, take a look at the following to insure you configuration is correct.

http://technet.microsoft.com/en-us/library/dd469733.aspx
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now