<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet Access from remote Branch in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4853024#M384891</link>
    <description>&lt;P&gt;I did NAT at branch internet router and it worked, thanks everyone for all of your inputs.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2023 13:51:22 GMT</pubDate>
    <dc:creator>optimusprime90</dc:creator>
    <dc:date>2023-06-12T13:51:22Z</dc:date>
    <item>
      <title>Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848134#M384458</link>
      <description>&lt;P&gt;Hi Dears,&lt;/P&gt;&lt;P&gt;We have remote branch connected to HQ via MPLS and IPSEC-GRE tunnel is configured on cisco routers on both ends. Both branches have separate DIAS internet links. Now I am looking to let one vlan subnet from HQ to use internet from remote branch internet connection, and stop this vlan to use local HQ internet connection.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 06:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848134#M384458</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-04T06:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848139#M384460</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1208203"&gt;@optimusprime90&lt;/a&gt;&amp;nbsp;if so you need to do route HQ vlan's internet traffic towards remote branch via tunnel and send our to internet via remote branch internet line. this is about routing and NATting&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 07:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848139#M384460</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2023-06-04T07:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848141#M384461</link>
      <description>&lt;P&gt;I Understand this is about routing and nating , can i get help about config setup please, and i do not want to route complete HQ internet traffic, I need to route only one subnet (one vlan)&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 07:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848141#M384461</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-04T07:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848151#M384464</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 07:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848151#M384464</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-11T07:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848159#M384466</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;This can most probably be accomplished with some traffic engineering however you dont mention what dynamic routing protocols&amp;nbsp; (if any) you are using,&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 07:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848159#M384466</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2023-06-04T07:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848174#M384469</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1208203"&gt;@optimusprime90&lt;/a&gt;&amp;nbsp;to give more specific support, please share the routing method you are using now (dynamic,static) and some details. then small network diagram to get an idea about traffic path and devices in between networks.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 09:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848174#M384469</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2023-06-04T09:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848202#M384477</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;Tunnel is set using static route, below is the topology example where we want to route that specific HQ subnet via branch internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12.jpg" style="width: 945px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186416i0B55A4AA8605AB7E/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.jpg" alt="12.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 12:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848202#M384477</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-04T12:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848221#M384478</link>
      <description>&lt;P&gt;Why do you wish to do this?&amp;nbsp; Reason I ask, it might be some what complex to accomplish, easy to inadvertently cause unexpected and undesired&lt;/P&gt;
&lt;PRE&gt;surprises&lt;/PRE&gt;
&lt;P&gt;in the future, and perhaps there's another easier/better way to accomplish your goal.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848221#M384478</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2023-06-20T09:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848223#M384479</link>
      <description>&lt;P&gt;one dept in HQ has work at some specific weblinks and those weblinks are not reachable via HQ internet due to some internal issues with ISP and website owners, that's why we want to redirect traffic of that department to our branch so they can work smoothly.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 14:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848223#M384479</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-04T14:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848236#M384482</link>
      <description>&lt;P&gt;Well, ideally, you would resolve the issue(s) with your HQ ISP and/or problematic websites owners.&lt;/P&gt;
&lt;P&gt;But, assuming you need to do something right now, where is NAT/PAT performed at HQ and branch?&amp;nbsp; How many special Internet website IPs is this a problem for?&lt;/P&gt;
&lt;P&gt;Any additional routers insider FWs at both sites, especially for VLAN at HQ that needs this treatment?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2023 15:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848236#M384482</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2023-06-04T15:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848263#M384492</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 07:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848263#M384492</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-11T07:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848404#M384505</link>
      <description>&lt;P&gt;NAT is configured on Our internet Router at remote branch and at Cisco IPSEC router at HQ.&lt;BR /&gt;currently we need to access to One website only.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 06:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848404#M384505</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-05T06:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848405#M384506</link>
      <description>&lt;P&gt;set the&lt;/P&gt;
&lt;PRE&gt;default route&lt;/PRE&gt;
&lt;P&gt;for that subnet to the interface or ip pointing to the remote branch, then use pbr to fine tune&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848405#M384506</guid>
      <dc:creator>Wizard4777</dc:creator>
      <dc:date>2023-06-20T09:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848409#M384509</link>
      <description>&lt;P&gt;you do port forwarding on the remote router&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 06:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848409#M384509</guid>
      <dc:creator>Wizard4777</dc:creator>
      <dc:date>2023-06-05T06:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848608#M384522</link>
      <description>&lt;P&gt;As I don't know all your routing topology's specifics, I can only suggest a conceptional approach.&lt;/P&gt;
&lt;P&gt;At HQ, add a static route, for the one problematic web site, on the IPSec router, to the internal facing interface IP on the branch Internet router.&amp;nbsp; This assumes, whether traffic gets to branch via MPLS path or tunnel, branch routing will get that outbound traffic to the branch Internet router.&amp;nbsp; It also assumes return traffic will be sent back to HQ (via branch).&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 13:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4848608#M384522</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2023-06-05T13:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851231#M384692</link>
      <description>&lt;P&gt;I did this static route, but it did not work.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 09:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851231#M384692</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-08T09:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851292#M384701</link>
      <description>&lt;P&gt;Unfortunately, without "seeing" all the configurations, including the static route you added, cannot suggest why it doesn't work.&lt;/P&gt;
&lt;P&gt;Have you tried something like a traceroute from the special HQ VLAN to the special web site to "see" the path being used?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 10:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851292#M384701</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2023-06-08T10:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851426#M384713</link>
      <description>&lt;P&gt;Yes i did tracrt from source machine, its reaching gateway and just dropping there, however from gateway which is firewll it should go to ipsec router.&lt;BR /&gt;i am copying static routes and tunnel config which we have currently.&lt;/P&gt;
&lt;PRE&gt;ip nat inside source list 10 interface Vlan300 overload&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 x.x.x.x --&amp;gt; public internet IP of HQ&lt;BR /&gt;ip route x.x.x.x 255.255.255.252 y.y.y.y (x is mpls ip of remote branch and y is mpls IP of HQ)&lt;BR /&gt;&lt;BR /&gt;IPSEC Tunnel:&lt;BR /&gt;&lt;BR /&gt;interface Tunnel400&lt;BR /&gt;ip address 172.16.80.12 255.255.255.0&lt;BR /&gt;no ip redirects&lt;BR /&gt;ip mtu 1440&lt;BR /&gt;ip nhrp authentication xxxxxx&lt;BR /&gt;ip nhrp map multicast dynamic&lt;BR /&gt;ip nhrp network-id 400&lt;BR /&gt;ip tcp adjust-mss 1360&lt;BR /&gt;ip ospf network broadcast&lt;BR /&gt;ip ospf priority 255&lt;BR /&gt;keepalive 3 3&lt;BR /&gt;tunnel source Vlan400&lt;BR /&gt;tunnel mode gre multipoint&lt;BR /&gt;tunnel key 400&lt;BR /&gt;tunnel protection ipsec profile MAT-PRO&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851426#M384713</guid>
      <dc:creator>optimusprime90</dc:creator>
      <dc:date>2023-06-20T09:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851474#M384717</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 07:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851474#M384717</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-11T07:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Access from remote Branch</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851614#M384730</link>
      <description>&lt;P&gt;". . . &lt;SPAN&gt;its reaching gateway and just dropping there, however from gateway which is firewll . . .&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;FW will allow traceroute replies?&lt;/P&gt;
&lt;P&gt;As to your route statement, where you want it to go, from HQ's IPSec router, is to the inside interface of the branch Internet router.&amp;nbsp; Basically, once it gets to the branch, you want it to follow branch's default to the Internet.&amp;nbsp; When traffic returns to the branch, you want it to come back to the HQ.&lt;/P&gt;
&lt;P&gt;What's also important, is how the branch is configured with routing and branch FW rules.&amp;nbsp; Keep in mind, the HQ traffic we're directing to the Internet, via the branch, branch setup may not be configured to support it.&lt;/P&gt;
&lt;P&gt;Again, conceptionally, this should work, but much depends on your overall configurations.&lt;/P&gt;
&lt;P&gt;Basically, what I've suggested is a subset of what the others were suggesting, i.e. redirecting HQ special subnet&lt;/P&gt;
&lt;PRE&gt;default route&lt;/PRE&gt;
&lt;P&gt;to the branch.&amp;nbsp; That too could work, but since you noted it's only one web site, couldn't see why you should need to send all that special HQ VLAN's Internet traffic via the branch.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/internet-access-from-remote-branch/m-p/4851614#M384730</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2023-06-20T09:27:35Z</dc:date>
    </item>
  </channel>
</rss>

