This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issues with IPSEC site to site traffic

Hello, 

I have an issue with my Site to Site connection. 

I have an IPSEC tunnel configured between a remote site and a head office. The remote site is an XG115 running V18 Mr1 and the Head Office (data centre) is an XG 230 running 17.5 mr9. 

The connection was working fine since before this weekend, however just decided to die over the weekend. 

Now, traffic is working between from the Head Office to the remote site, but is NOT working from the remote site to resources in the head office. 

What I have noticed is when running a packet capture on the remote site to analyse where the traffic is going, the source seems to appear from the Public IP of the remote site. I would expect it so show the remote site internal IP to the head Office internal IP. I believe the issue is with NAT, and that traffic from the remote site is being NAT'd to the external IP, and hence the return traffic not getting back. 

I was wondering if this is something anyone else has come across?

 

I have NAT disabled in my IPSEC configuration, also my NAT rules only contain the default rules for source NAT for external traffic. 

I have tried creating a NAT rule for the destination network but no luck. 

I have tried adding an IPSEC route manually but this did not work.

I have deleted the tunnel configuration and recreated and this did not work. 

I created a tunnel to another remote site of ours and get the same issue.

 

Thank you



This thread was automatically locked due to age.
Parents Reply Children
  • Here is a screenshot of the remote site:

     

    Here is a screenshot of the data centre: (blanked out sensitive info)

     

    Here is the PING result from the remote site to the datacentre: (blanked our sensitive info, but the 81. address is the remote site public IP, 172.16. is the data centre server IP, the 10. address is a client I am initiating PING from). 

     

    This is the packet capture (from the remote site Sophos) when I PING from the datacentre server to the remote site workstation: (PING is successful)

     

    When I run the packet capture on the Data Centre Sophos, while running a PING from the remote site to the data centre server there are no results. 

    Packet capture would look something like: dst host *Data centre server local IP*