Got it

Internet access through IPSec

Created: Oct 14, 2021 20:15:01Latest reply: Oct 18, 2021 20:22:09 207 4 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,


I have an IPSec tunnel between a branch and an headquarter (both AR611w connected to the ISP router on both ends).

The tunnel is working, I can ping hosts in the LAN both ways, but how can I have the branch (and headquarters) to have internet through the headquarters internet access?

Featured Answers

Recommended answer

fuzi_yao
Admin Created Oct 15, 2021 00:44:12


Hi EuricoD,
You can add the network segment for the branch to access the network to the ACL of the headquarters,
and direct the route to the headquarters at the branch.
View more
  • x
  • convention:

All Answers
Hello! Thank you for contacting us.
We are working on an answer for you.
View more
  • x
  • convention:


Hi EuricoD,
You can add the network segment for the branch to access the network to the ACL of the headquarters,
and direct the route to the headquarters at the branch.
View more
  • x
  • convention:

Good answer
View more
  • x
  • convention:

bruno.guedes
bruno.guedes HCIE MVE Author Created Oct 18, 2021 20:22:09

You could configure a DSVPN among them and implement a routing protocol like OSPF. Then, you could originate a default route just in the site where you intend to have the traffic being sent to the internet (all other sites will learn that this site is the default to reach any other address).

Check this example:

https://support.huawei.com/hedex/pages/EDOC1100203017AEK07051/02/EDOC1100203017AEK07051/02/resources/dc/dc_ar_cfg_vpn_045539.html?ft=0&fe=10&hib=8.3.6.3.2&id=EN-US_TASK_0176365505&text=Example%20for%20Configuring%20DSVPN%20to%20Allow%20Branches%20to%20Learn%20Only%20Summarized%20Routes%20to%20the%20Headquarters%20and%20Implement%20Communication%20Between%20the%20Branches%20(Applicable%20When%20There%20Are%20a%20Large%20Number%20of%20Branches)&docid=EDOC1100203017

Do you know how to generate a default route on OSPF? You just got do it in HQ in this example. In this example, he uses the RIP as the routing protocol interconnecting the sites, but you can use the OSPF.


View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.