cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
557
Views
0
Helpful
2
Replies

dual wan ios router with pbr and RAS IPSEC VPN

sebastiangille
Level 1
Level 1

Hi,

 

i configured a cisco ios router 871 - Adv IPservices Version 12.4(24)T8 with a dual wan configuration and ipsec ras vpn.

Everything works perfect, expect RAS IPSEC VPN.

a global policy route map is configured:

ip local policy route-map vpn-access

...

ip access-list extended vpn
 permit udp host [vpn-traffic-wan-interface-ip] eq isakmp any
 permit tcp host [vpn-traffic-wan-interface-ip] eq 10000 any
 permit esp host [vpn-traffic-wan-interface-ip] any
 permit udp host [vpn-traffic-wan-interface-ip] eq non500-isakmp any

........

route-map vpn-access permit 10
 match ip address wpn
 match interface FastEthernet4
 set ip next-hop [vpn-traffic-wan-interface-gw]

two default routes, the one for vpn-traffic with a higher metric.

The vpn client connects to the router, traffic from vpn client to the remote net arrives, but the reverse not.

I created a virtual template with a policy route-map, so that the vpn net is forced to be routed outside the vpn-traffic-wan-interface,i also configured a default route for the vpn-client-net outside to vpn-traffic-wan-interface-gw

If i delete the primary default route (lower metric than vpn-traffic route) everything works as expected.

My next step would be a packet capture on the router to check how the traffic flows (it seems that the reverse traffic passes the lower metric route)

 

Where is the mistake, i'm quite sure that i configured a working scenario the same way before, unfortunately i'm not able to verify it (config lost)

Thanks

 

 

 

2 Replies 2

Hello, Sebastian.

Per my understanding you are trying to tunnel IPSec traffic via one interface and all the other (browsing) traffic over another.

If yes, I would suggest, is to use 0.0.0.0/0 over VPN interface and do client traffic PBR.

 

PS: VTI transport traffic is not subject to local PBR, I guess ESP could be as well.

Hi Vasilii,

your understanding is correct.

I will try it with your suggestion.

 

Regards

Review Cisco Networking for a $25 gift card