cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
481
Views
2
Helpful
3
Replies

IPsec tunnel

KayaaKashyap
Level 3
Level 3

74329707-7c56-4b6a-bf03-c467efd1ec89.jpeg

 Hi, Please check network and query in attached image. Help me to get solution on this.

3 Replies 3

@KayaaKashyap hi, this is very wide question since there are no all details about setup. generally, i can say below approach. 

1. since you have SDWAN you may need to create a SDWAN policy for relevant colour/tloc/DC/VPN to prioritize traffic via manual IPSec.

2. if there is no routes, you need to check and add required routing in SSE, FW01 and other locations.

3. in SSE and SW01 you need to do proper firewall rules to allow required traffic.

4. additionally make sure all routes are properly configured to avoid asymmetric routes

 

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

@KayaaKashyap Most probably it will be possible. What are the current VPN tunnel endpoints platforms, the SDWAN and FWaas from your diagram?

Thanks,

Cristian.

Catalyst sdwan to sse auto vpn

Now we are planning to create new parallel tunnel between catalyst to sse
Then we will migrate