- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-04-2025 04:02 PM
good afternon
for example my ISP give me data link with ip address 192.168.20.2/28 this interface i connect to my interface 1/1 ok this work like my WAN, when i create ipsec tunnel i put same ip address on proxy ID 192.168.20/2/28 peer 10.10.10.10 this its possible ? work o have some issues with routing because en static route i have 0.0.0.0/0 next hop 192.168.20.2/28
06-05-2025 03:07 AM
the proxyID is only used to negotiate tunnel SAs so doesn't impact routing
you can put anything you like in there, if it makes sense to put it there in the first place
will connections go into the ipsec tunnel that originate from the 192.168.20.0/28 subnet ?
ProxyID is set to negotiate which source subnet (clients) is allowed to communicate over the tunnel with a destination subnet (servers), so typically your local 'trust' and the remote 'trust' subnets are in the proxyID, while the untrust IP is only used in the IKE Gateway object to negotiate the tunnel itself
06-05-2025 03:07 AM
the proxyID is only used to negotiate tunnel SAs so doesn't impact routing
you can put anything you like in there, if it makes sense to put it there in the first place
will connections go into the ipsec tunnel that originate from the 192.168.20.0/28 subnet ?
ProxyID is set to negotiate which source subnet (clients) is allowed to communicate over the tunnel with a destination subnet (servers), so typically your local 'trust' and the remote 'trust' subnets are in the proxyID, while the untrust IP is only used in the IKE Gateway object to negotiate the tunnel itself
06-06-2025 08:43 AM
thanks for ask my question
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!