We have setup a IPSEC Site to Site VPN between our ASG220 and a Juniper firewall on the remote site. The only issue is that the automatic packet filter rules don't seem to be working properly. Currently, the only way we can get all necessary services to work from the Juniper side is to have a packet filter rule enabled to allow Any > Any > Internal Network. As soon as that rule is disabled we lose the ability to do anything from the Juniper site other than was is already allowed on the Astaro, such as Ping and HTTPs access to the Astaro. Services from the Astaro side to the Juniper side, such as RDP still work fine with that rule disabled.
We have also added the following manual Packet Filter rules with no success:
Remote Site LAN > Any > Internal (LAN) Network
Remote Site WAN > Any > Internal (LAN) Network
Remote Site LAN > Any > External (WAN) Address
Remote Site WAN > Any > External (WAN) Address
Obviously, we don't want to leave the current rule (Any > Any > LAN) enabled, so any help would be appreciated.
This thread was automatically locked due to age.