08-25-2017 08:37 AM - edited 03-12-2019 04:30 AM
Hello,
I have re-configured 1921 router on a branch with zone based firewall, after this my site to site VPN tunnel is up but traffic is only one way, I can only access from branch office 192.168.73.0/24 to head office 192.168.70.0/24 but not from head office to branch office please see the config attached of the branch office 1921 router. Head office got ASA5510, before re-configuring of 1921 router site to site vpn was working fine.
X.X.X.X is the public ip address of the Head office
Y.Y.Y.Y is the public IP address of the branch office
Thanks
Hasrat
08-25-2017 09:55 AM
Hi Hasrat,
I think you'll need zone pairings from WAN to LAN in addtion to the zone pairings from LAN to WAN.
E.g - zone-pair security ZP-SFINVER-WAN-to-LAN source Z-SFINVER-WAN destination Z-SFINVER-LAN
You'll need to repeat this for the other zones Z-SFINVER-GUEST and Z-CR-LAN
HTH
11-27-2017 04:36 AM
sorry for late reply, it worked, just need some Access list sorted
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: