Routing internet traffic (only specific domains) through double sNatted IPSec VPN




Good morning
i need to route web traffic towards specific domain through a IKEv2 ipsec vpn between two sites with overlapping subnets.
Scenario
Site A (natted wan ip, can't change nats) calls site B (natted wan ip, CAN change nats) and establish ipsec vpn "site to site with dynamic peer scenario".
Both sites have sNAtted outbound traffic and related dNat.
All traffic to sNatted subs is routed by policy routes and works well (or at least, i can ping).
Then i tried routing some FQDN addresses (mioip.it) from site A to site B through ipsec tunnel but i can't get it to work.
Here some screens of routing policies i'm using:
Any advices?
All Replies
-
So the idea is to route mioip.it out the internet of site B Ok not as simple as it looks as many sites have other address and CDN to load as part of mioip.it so if you don't include the other FQDN which is best to be done as *.mioip.it (which include subdomains) the site may not load.
Also you need site B not to have destination mioip.it and set to any
By doing *.mioip.it you need the PC to do ipconfig /flushdns so that the PC relooks up the DNS for USG to see it
try something simple first to get it working like
FQDN
*.dyndns.com
and go to
Also you must use in the clear DNS no DNS over HTTPS
0 -
Also on site B you need a routeing rule to forward the return traffic to VPN tunnel
incoming any
destination address of outgoing traffic form tunnel
next hop VPN tunnel
0 -
thank you for your reply,
i'm trying this tomorrow and i'll let you know
0
Categories
- All Categories
- 417 Beta Program
- 2.5K Nebula
- 160 Nebula Ideas
- 108 Nebula Status and Incidents
- 5.9K Security
- 331 USG FLEX H Series
- 286 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 259 Service & License
- 402 News and Release
- 86 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 80 Security Highlight