Question
Can only Access One Subnet on Established VPN
[tl;dr version: VPN tunnel established between to FGs (101c/80c), cannot access 80c network but can access 101c network, both vanilla FGs, 4.0M3 Zzzzzzzz] I admit defeat. Here is my issue. I have two VPNs set up, one between a 110c and an 80c and one between the same 110c and a SonicWall device. In both cases (and it doesn' t bother me with the SonicWall, I bring it up as extra evidence of VPN horror), NAT works from outside the 110c *to* the network behind the 110c but NAT does not work from inside the 110c network *to* the other networks (the only important one being the internal network behind the 80c). For example, the 110c is internally a 10.10.10.0/24 network with a public gateway of 192.168.100.100. The 80c is internally 10.100.100.0/24 with a public gateway of 172.16.200.200. With the tunnel established, I can ping any 10.10.10.0/24 host from any host within the 10.100.100.0/24 network. I cannot however, ping any 10.100.100.0/24 host from any host within the 10.10.10.0/24 network. The same is true with the SonicWall tunnel. My ulcer is laughing. 101C SETTINGS: The 101c IPSEC phase 1 is (all example IPs): Remote Gateway: 172.16.200.200 Local Interface: Public WAN interface Mode: Main Pre-shared key No advanced options The 101c IPSEC phase 2 is: Set to the appropriate phase 1 object (Standard Advaced options: enable replay detection, PFS, autokey keep alive) Quickmode Selector: Source address: 10.10.10.0/24 (tried with address object also) Destination address: 10.100.100.0/24 Policy: Source: internal_interface Source Addr: 10.10.10.0/24 address object Destination Interface: external_interface Destination Addr: 10.100.100.0/24 address object Schedule: whenever I want Service: whatever I want Action: IPSEC VPN Tunnel (correctly chosen): Allow Inbound, Allow Outbound, Inbound NAT 80C SETTINGS: The 101c IPSEC phase 1 is (all example IPs): Remote Gateway: 192.168.100.100 Local Interface: Public WAN interface Mode: Main Pre-shared key No advanced options The 101c IPSEC phase 2 is: Set to the appropriate phase 1 object (Standard Advaced options: enable replay detection, PFS, autokey keep alive) Quickmode Selector: Source address: 10.100.100.0/24 (tried with address object also) Destination address: 10.10.10.0/24 Policy: Source: internal_interface Source Addr: 10.100.100.0/24 address object Destination Interface: external_interface Destination Addr: 10.10.10.0/24 address object Schedule: whenever I want Service: whatever I want Action: IPSEC VPN Tunnel (correctly chosen): Allow Inbound, Allow Outbound, Inbound NAT I have tried everything I know to do other than set natip, which I think I shouldn' t need to do. Again, there is no issue accessing resources from one subnet to the 101c subnet, but there is no way to access other subnets from the 101c network. Any help would be greatly appreciated OMG you have no idea how much.
