Project

General

Profile

Actions

Feature #9230

closed

The ability to port forward across an IPSEC site to site vpn

Added by Dan Tentler over 5 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
12/27/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:

Description

In my environment, have a 7100 in a colo, and it is attached to a remote office via a site-to-site ipsec vpn link.
In the office, I have a mailserver, and I wish to allow traffic to flow to that mail server across the vpn link. Here is a very simple diagram:

internet -> colo firewall -> ipsec vpn link -> office firewall -> lan -> mailserver

Ideally, I'd like this to function as a 1:1 nat, as though it would without the ipsec link, so that all traffic into and out of that mailserver goes over a dedicated IP at the colo. It seems like it would work, so I tried it and the traffic wouldn't flow. I asked support about it, and they said that it was unsupported.

This is fairly high priority for us, as due to an unanticipated network change we've been forced to adopt this architecture, and this mail server is down until we can sort out how to get mail to flow to it.

Actions

Also available in: Atom PDF