Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Policy based site2site VPN no traffic

$
0
0

Assuming you have a default outbound source nat policy, you want to add something like  this to the nat rule to exclude the VPN traffic.

 

set security nat source rule-set trust-to-untrust rule vpn match source-address 10.0.100.0/24
set security nat source rule-set trust-to-untrust rule vpn match destination-address 192.168.178.0/24 
set security nat source rule-set trust-to-untrust rule vpn then source-nat off 
insert security nat source rule-set trust-to-untrust rule vpn before rule source-nat-rule 

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>