Policy route to wan via specified wan
Hello!
We use USG 1100 with 2 wan interface in trunk. Added policy route for ipsec with other office via vpn gates and to wan via trunk.
Now need to add special routes for some device via specified wan. I add policy route, in interface set interface with device, set device address, set next hop is needed wan interface. Destination haven't option wan-zone. So i set any. And device route to wan via specific wan, but don't see remote office via ipsec.
How can i set policy route for the device only to wan zone, to ipsec via standart routes?
We use USG 1100 with 2 wan interface in trunk. Added policy route for ipsec with other office via vpn gates and to wan via trunk.
Now need to add special routes for some device via specified wan. I add policy route, in interface set interface with device, set device address, set next hop is needed wan interface. Destination haven't option wan-zone. So i set any. And device route to wan via specific wan, but don't see remote office via ipsec.
How can i set policy route for the device only to wan zone, to ipsec via standart routes?
0
Comments
-
Hi @alexey,
You have to create another policy route for site to site VPN connection.
e.g.
Incoming interface = ge3
Source = ge3 local lan subnet
Destination = Remote site lan subnet
Next Hop = Site to Site VPN connection.Prioiry = This policy route rule proiority must higher than other policy route0
Categories
- 7K All Categories
- 1.4K Nebula
- 29 Nebula Ideas
- 35 Nebula Status and Incidents
- 3.9K Security
- 200 Security Ideas
- 718 Switch
- 29 Switch Ideas
- 596 WirelessLAN
- 8 WLAN Ideas
- 4.5K Consumer Product
- 97 Service & License
- 215 New and Release
- 38 Security Advisories
- 499 FAQ
- 220 Nebula FAQ
- 120 Security FAQ
- 72 Switch FAQ
- 66 WirelessLAN FAQ
- 5 Consumer Product FAQ
- Documents
- 30 Nebula Monthly Express
- 43 About Community
- 31 Security Highlight