I'm trying to get a IPSec link running where one end is on the protected side of ASL. The IPSec link is setting up OK, but when I try and use the link, ASL is blocking the ESP packet to the to other end (seen in live log).
Any ideas?
Config. details:
ASL 2.022
Internal LAN is Mask'd
Both hosts defined in networks
UDP 500 and ESP SPI: 254:65535 defined as services
UDP+ESP defined as service group
Packet filter rules:
External host UDP+ESP Grp Internal host Allow
Internal host UDP+ESP Grp External Host Allow
DNAT Setting:
ASL Red IP UDP500 Inetnal host UDP500
I feel as though something is missing from this DNAT setting letting ASL to permit/forward ESP packets to the Internal host, but the UDP+ESP group isn't an option.
I hope you can help.
PS. I have tried changing the SPI to the range 254:40000000+ (I forget the exact number, I found it in version postings).
This thread was automatically locked due to age.