We have 2 ASG220 with IPSec VPN 7.403
AS A needs to be the default GW for all internal networks, including the internal network of AS B
on AS A (Default GW) in IPSec->Connections->LocalNetworks we include and "Any"
On AS B in IPSec-> Remote Gateways -> Remote Networks we include "Any"
That way AS A is the single point for NAT / Proxy / Packet Rules etc.
Once the VPN tunnel with IPSec is up, it works fine, EXCEPT AS B is not reachable (ping, https) on it's public address anymore.
Without the "Any" definition, AS B is reachable from public, but would have to do it's own NAT etc.
Strict Routing on or off makes no difference.
Any clue ?
This thread was automatically locked due to age.