Scenerio:
IPSEC Net to Net - ASL 4.018
192.168.0.0/16 internet --- internet 192.168.234.0/24
Problem is that when the IPSEC tunnel is brought up, I lose the ability to ping, and/or talk to the internal interface on the 192.168.234.0 side from that subnet whatsoever. I am able to communicate with it from the remote end (with its internal 234.1 ip) however. (NOTE: the firewall still routes traffic fine, it just isn't responsive to traffic intended for its internal interface)
When the tunnel is brought down, all communications on the 234 side to the firewall work fine (able to webadmin, ping, etc the internal interface). This problem does not show up when the /24 side of the tunnel is running ASL 2.x.
It would seem there is an issue with routing in 4.x that leads ASL to ignore the fact that the /24 netmask is more granular than the /16 that was not present in the 2.x versions of ASL.
Anyone experienced this or have any idea as to why it is happening?
This thread was automatically locked due to age.