dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
3528

ayeee
@83.254.126.x

ayeee

Anon

Multiple subnets over IPSec-tunnel

Hi all,

I have a problem were I want to enstablish an IPsec VPN-tunnel on which I got multiple local subnets. When creating a VPN Connection (VPN > IPSec VPN) I get stuck on the "Local policy"-definition. This option only allows me to specify one address object rather than multiple. This may be by design, but then I would like some guidance on how to proceed.

Here's some information about the endpoints and their subnets.
[HQ] (USG 20W)
192.168.0.0/24
10.151.4.0/22

[Cloud Partner]
10.151.12.0/22

As seen, the "Remote subnet" can be defined in an address object. However,
How would you define the "Local subnet"-address object? ..or is there any other way?
gb5102
join:2003-10-07
Saint Paul, MN

gb5102

Member

You would configure 2 separate VPN Connections, one for each subnet, both using the same VPN Gateway.

Not quite as 'clean' as Cisco for example where you can have different subnets in an access-list, but it works the same in the end...

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON
(Software) OPNsense
Ubiquiti UniFi UAP-AC-PRO
Ubiquiti NanoBeam M5 16

Brano to ayeee

MVM

to ayeee
As already suggested, creating multiple tunnels is the solution.

Alternatively you could re-number your HQ networks and create one tunnel for larger range, for example:
Keep 192.168.0.0/24 renumber the other network to 192.168.1.0/24 and then you can create VPN tunnel for range 192.168.0.0 - 192.168.1.255.

ayeee
@192.71.246.x

ayeee

Anon

said by gb5102:

You would configure 2 separate VPN Connections, one for each subnet, both using the same VPN Gateway.

Not quite as 'clean' as Cisco for example where you can have different subnets in an access-list, but it works the same in the end...

said by Brano:

As already suggested, creating multiple tunnels is the solution.

Alternatively you could re-number your HQ networks and create one tunnel for larger range, for example:
Keep 192.168.0.0/24 renumber the other network to 192.168.1.0/24 and then you can create VPN tunnel for range 192.168.0.0 - 192.168.1.255.

Thank you both. The new VPN Connection with the other subnets was enstablished.