Hello,
i have an XG in a branch office with a VPN tunnel to the main office with any-any rules both ways, main office has a UTM with the AD servers, stas is already configured there.
the fixes for the broken xg net to net vpn funcitonality are also applied(there's an ipsec route added for the entire main office network through the tunnel and also two NAT system policies for each DC for the DNS request routing bug)
for the STAS config:
in each DC i added the XG LAN IP as appliance in the STA collector page with subnet mask filter(for the remote subnet only)
added the remote subnet to the monitored list
but when i go to advanced and test connection to the appliance it fails.
when checking the XG FW log i see that the system is dropping UDP 6060 packets coming from the DC:
2017-04-06 11:27:35
|
Local ACL
|
Denied
|
-
|
0
|
ipsec0
|
-
|
10.10.10.35 :UDP (57577)
|
10.10.20.1 :UDP (6060)
|
This thread was automatically locked due to age.