4 Replies Latest reply on Jun 20, 2014 11:32 AM by sliedl

    Site to Site VPN and Routing for the vpn destinations

    snikhil03

      I have an MPLS link over which i am trying to build a Site to Site VPN

       

       

      Ip Of my MPLS Interface is 172.16.10.1 (this interfce zone is MPLS)

      I have Internal IP range in 192.168.10.0/24

      I have to NAT 192.168.10.0 behind 172.16.30.1/32 IP

       

       

      I have done the following conifguration on the firewall

       

       

      1.Enabled ISAKMP Server from MPLS Zone to MPLS from Any to Any

      2.Created a New Virtual Zone called VPN

      3.Configured VPN under VPN Definition and selected the Zone as VPN

        My Gateway is 172.16.10.1  Peer Gateway is 172.16.10.2

      4.Created the Policy from Internal to VPN Zone for permitting traffic from 192.168.10.0/24 to Destination Range 10.10.1.0/24

        In the policy ,selected the NAT IP as 172.16.30.1/32

       

       

       

       

      However I do not see any activity related to tunnel initiation in the Firewall

      Would like to confirm if the steps are correct  especially on the Zone configuration

       

       

      Also  Do I have to add  routing for 10.10.1.0/24 ?If yes what is the Next Hop IP i should give

       

       

      Can someone help me ?