News: This forum is now permanently frozen.
Pages: [1]
Topic: In a VPN: users of B , for go out, must NATing with the IP pubblic address of A.  (Read 2745 times)
« on: November 11, 2010, 12:57:09 »
robicarta *
Posts: 4

Hello everyone  Smiley,

I'm going crazy to find a solution to my problem.  Huh
At this point I do not know what to do ... I therefore appeal to your help.

I created a VPN IPSEC [LAN officeA (with public IP monowall 85.XX.XX.XX)] to [LAN officeB (monowall with public IP 88.XX.XX.XX)], which works perfectly;

Now I would like to create a compulsory path, in order to reach a specific internet website (for example https: / / 19545.com/test/subMenu.do? menuId = 40 #),
all clients from officeB must go out from the gateway in officeA (192.168.20.254), in short.. to reach that domain, users must NATing with the IP pubblic address of officeA.

I tried a static route to the gateway of officeA (192.168.20.254) .. It doesn't work since only through the tunnel you can reach that destination.

The LOGS show that gateway is unknown. Ping and Traceroute the same.

 LAN (192.168.20.254) Green
 |
 WAN (192.168.1.2) Red
Monowall
 |
-ROUTER (NAT)
 |
officeA (85.XX.XX.XX)
 |
 |
 tunnel (IPSec NAT-T enabled)
 |
 |
officeB (88.XX.XX.XX)
 |
-ROUTER (NAT)
 |
Monowall
 WAN (10.10.10.2) Red
 |
 LAN (192.168.10.254) Green

Thanks in advance x the help ...  Wink

Robicarta
« Reply #1 on: December 09, 2010, 16:20:07 »
robicarta *
Posts: 4

 nothing? Cry
« Reply #2 on: December 11, 2010, 10:40:30 »
Јаневски ***
Posts: 153

If You're not using Outbound NAT then try adding static route as You did from the previous to the other host, but this time don't forget to add another "route-back" from the other host to the previous host.

A -route-> B
B -route-> A
« Last Edit: December 11, 2010, 10:43:26 by Јаневски »

« Reply #3 on: December 11, 2010, 15:52:40 »
robicarta *
Posts: 4

hi Јаневски,

in static route, only Gateway to be used to reach the destination network.

The gateway of officeA (192.168.20.254) doesn't work since only through the VPN tunnel you can reach that destination.

the IP "192.168.20.254" is not accepted by m0n0wall as gatewey because it's not a gateway. Undecided

anyway thanks x your reply.  Smiley

 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines