This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multilink & VPN-IPSEC problem

Hi, 

I have a pair of Astaro 220 ASG in HA standby cluster with 7.401 version installed.

Now, I have two data access, DSL connection and Fiber Optical with ethernet port to the ASG.

We use FO to make VPN-IPSEC against some services with an astaro in the end point and DSL to make another VPN-IPSEC against other services with a Junniper in the end point.

I have disabled all routing rules, to merge in multipath rules coz I have set the uplink mode in "multipath". First FO, second DSL.

In VPN-IPSEC settings I have selected in the dropdown list the "uplink interfaces" and in Masquerading too.

So I have defined two multipath rules:

1) Source Any , Service Any, Destination Public IP Astaro, itf persistance "by interface", bind interface FO
2)Source Any , Service Any, Destination Public IP Junniper, itf persistance "by interface", bind interface DSL

So the problem was with this settings ALL VPN-IPSEC tunnels goes to FO connection and I couldn't establish the tunnel to the junniper.

What I need to change in the multipath rules or in IPSEC to send packets to differents VPN's through differents connections in multipath scenario?

regards


This thread was automatically locked due to age.
  • I believe there's been some patches related to multipath since 7.401; I recommend that you up2date your appliance to Version 7.509.

    Also, I wouldn't use ANY in those definitions... use "Internet" or a more specific definition in those rules.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • thanks, on Monday I will try to update the system.

    Also i had tried with more specific definitions on the "source" in the multipath rule with the same result.

    thanks in advance.

    regards