Skip to main content
hxcsp
New Member
November 8, 2017
Question

Site-To-Site VPN > Multiple Subnets

  • November 8, 2017
  • 1 reply
  • 16089 views

Hello,

 

I am having an issue with reaching a certain subnet over a VPN tunnel.

 

Site A: 10.50.1.1/24

Site B: 10.0.1.4/16

Phone Network: 172.21.0.0/16

 

Site A and Site B are connected via VPN Tunnel

Site A needs to reach Phone network.

Phone network is reachable via a Gateway at SiteB: 10.0.1.1

 

Currently, Site B can reach the phone network via Static Route.

I have a static route at Site A routing Phone network through the VPN Tunnel Interface.

 

My VPN Tunnel From A to B has two Phase 2 subnets: 10.0.0.0/16 and 172.21.0.0/16

Firewall Policies are in place to allow traffic from 10.50.1.0/24 to 10.0.0.0/16 AND 172.21.0.0/16    and vice versa.

 

When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.

Is there something I am doing wrong? Remote sites need to reach the Phone network via Site B's alternate gateway 10.0.1.1.

Thanks in advance.

    1 reply

    emnoc
    New Member
    November 8, 2017

    When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.

     

    check router table

     

    cli   get router info rout all

     

    MikePruett
    New Member
    November 8, 2017

    verify the route on device A is in place.

    verify the tunnel has phase 2's in place to allow the traffic