cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
684
Views
0
Helpful
2
Replies

IPSec site to site VPN possible acl issue

roharris33
Level 1
Level 1

I have conifigured a IPSEC tunnel between a remote site and the corporate office. I configured the IP helper on the interfaces so the devices will contact the corporate DHCP server....so nothing is natt'ed. The tunnel comes up just fine. I can access the loopback from the corporate office but nothing else. None of the clients are picking up an IP address. The routing looks good but when I perform a trace from the far end to the head end it doesn't look like the trace is leaving the far end's interface. I suspect its an acl issue but my acl's look good. Any ideas? 

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - You need to allow multicast over VPN too, check this link :

 https://www.draytek.com/en/faq/faq-vpn/vpn.others/how-to-use-dhcp-relay-over-an-ipsec-tunnel/

M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

View solution in original post

2 Replies 2

marce1000
VIP
VIP

 

 - You need to allow multicast over VPN too, check this link :

 https://www.draytek.com/en/faq/faq-vpn/vpn.others/how-to-use-dhcp-relay-over-an-ipsec-tunnel/

M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Thanks for the reply. I can't ping anything on the corporate network. I can't even ping the gateway of the tunnel. So I don't think this is a multicast issue. My route map is pointing to the gateway of the tunnel, and I've applied that statement to the VLAN's interfaces. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: