Site to Site IPSEC problems
Hi!
We have some problem with routing? via IPSec site to site
1. 2 ISP on both side, 4 ipsec tunnels from Branch site (60c) to mail office (1000c).
2. Phase 2 on all tunnels 0.0.0.0/0.0.0.0 as networks, static routes with different distance (1-2-3-4) for IPSEC failover.
3. "LAN" 192.168.7.0/24 on 60С and "LAN" 192.168.0.0/24 on 1000C
4. FW on 60c and 1000c 5.2.11 latest
5. All work fine, traffic flow from any LANs to any LANs via IPSec BUT ...
If trace route from LAN 192.168.0.0 host to host in 192.168.7.0 i see, WAN1 IP of 60C in trace route ....
1 <1 ms <1 ms <1 ms 192.168.0.251 (1000C LAN IP) 2 3 ms 3 ms 2 ms xx.xx.xx.xx (60C WAN1 IP) 3 3 ms 2 ms 2 ms host5 [192.168.7.1] (host in 192.168.7.0 network)
Why traffic flow like this ??? We have few others devices connected same way - no tracert problems!!!
We try check any settings - all the same, only difference - connected ports. We think - traffic flow as ifindex of port on FGT ????
How we can resolve issue?
We have troubles with applications like TMG 2010 - client source IP (WAN IP 60c) unreachable in logs ...
Tnx for any help!
