This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Ambiguity in manual for SD-WAN policy destination

Manual notes the following, but WAN is not an option.

Check if an SD-WAN policy route has Destination networks set to Any.

Change the setting from Any to a specific choice (example: WAN) from the list. Setting it to Any forces XG Firewall to forward internal traffic also to the WAN interface.

 

This seems like a very easy solution to my problem of all VPN SSL traffic appearing to try routing out the WAN interface.

I am using OSPF routing for the network, and precedence is sd-wan. vpn, static, and I have no static routes.

Am I missing a workaround to the possible Any/Any issue?



This thread was automatically locked due to age.
Parents Reply
  • LuCar,

    All it took was getting a new range for the remote VPN network, and adding to the OSPF table. 

    I think my initial problems were firewall or sd-wan rule related, so I reverted, and found I didn't need, the "Example: console> system route_precedence set static sdwan_policyroute vpn". Just in case I am missing something related to this, please nudge me back to your suggestion.

    Thank you maestro, for your time and patience.

    Paul

Children
No Data