Skip to main content
Vineeth_U
New Member
March 1, 2016
Question

VPN Unable to Configure

  • March 1, 2016
  • 1 reply
  • 2192 views

Dear Team,

 

I am in the process of a VPN Implementation for one of the client. We have successfully configured Phase 1 but phase 2 is not coming up. I have configured this as Interface Based VPN. 

Client has given few destination IP Address those are Public IPs. I have few questions here, How do I configure this in the phase 2. How do I create policy for this. Is a Static Route required for this. ?

 

PLease help me to configure.

 

1 reply

emnoc
New Member
March 1, 2016

yes and yes  ;)

 

1: a interface-vpn ( aka route-vpn ) needs a route

 

2: just stick the src-subnet(s) in your  phase2-interface cfg

 

3: if your new at lan2lan vpn, the vpn wizzard should be ideal

 

What's on the other end? ( SRX ASA  FGT  )

 

Do you have any subnet overlap issues ?

 

Do you need to SNAT the internal hosts?