its possible have the same ip on proxy id on ipsectunnel and interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

its possible have the same ip on proxy id on ipsectunnel and interface

L0 Member

good afternon

 

for example my ISP give me data link with ip address 192.168.20.2/28 this interface i connect to my interface 1/1 ok this work like my WAN, when i create ipsec tunnel i put same ip address on proxy ID 192.168.20/2/28 peer 10.10.10.10 this its possible ? work o have some issues with routing because en static route i have 0.0.0.0/0 next hop 192.168.20.2/28

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

the proxyID is only used to negotiate tunnel SAs so doesn't impact routing

you can put anything you like in there, if it makes sense to put it there in the first place

 

will connections go into the ipsec tunnel that originate from the 192.168.20.0/28 subnet ?

 

ProxyID is set to negotiate which source subnet (clients) is allowed to communicate over the tunnel with a destination subnet (servers), so typically your local 'trust' and the remote 'trust' subnets are in the proxyID, while the untrust IP is only used in the IKE Gateway object to negotiate the tunnel itself

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

the proxyID is only used to negotiate tunnel SAs so doesn't impact routing

you can put anything you like in there, if it makes sense to put it there in the first place

 

will connections go into the ipsec tunnel that originate from the 192.168.20.0/28 subnet ?

 

ProxyID is set to negotiate which source subnet (clients) is allowed to communicate over the tunnel with a destination subnet (servers), so typically your local 'trust' and the remote 'trust' subnets are in the proxyID, while the untrust IP is only used in the IKE Gateway object to negotiate the tunnel itself

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L0 Member

thanks for ask my question 

 

  • 1 accepted solution
  • 211 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!