I have a brand new XG 125 installed in Factory Status with SFOS 18.0.1.
- Current precedence for routing: SD-WAN policy route, Static route, VPN route
- Policy route also applies to system-generated and reply traffic
With these settings I'm still having routing issues.
I have set a tunnel-based IPsec VPN connection.
The routings to the networks behind the VPN are SD-WAN Policy Routings.
For the normal traffic of clients behind the XG the SD-WAN Policy Routing is working fine.
But there are exceptions:
- VoIP traffic
I have a phone system that is behind the IPsec VPN. When I initiate the connection my voice packets are not routed correctly.
I can listen to the other side, but the other side doesn't hear me.
With packet capture I can see that my voice packets are routed to the WAN interface.
Only after entering a static routing for the network of the phone system did my packets route through the VPN
When the other side initiates the connection I have no issues.
I had the same issue with VoIP also with another XG 125 that was updated from 17.5.12 to 18.0.1 - System DNS traffic
I have a series of DNS routes set in the XG. The DNS servers are behind the IPsec VPN.
Here too I can see that the DNS requests are being routed to the WAN.
Here too, only after entering a static routing did the system-initiated DNS requests go into the tunnel.
In my understanding this should not be so.
SD-WAN Policy Routing should do all the routing for the configured networks and should not require static routing.
Are these problems I'm encountering a real issue, or am I missing something?
This thread was automatically locked due to age.