We are working with a datacenter to get VPN tunnels set up between their two sites and an overseas office. We configured our local office easily on our SonicWALL device for this, but we're having trouble getting the Untangle device (it is one of the Untangle boxes that is sold) set up and basically all of our trouble is because neither I or our tech across the pond know exactly what to do. I've tried looking at the demo for Untangle, but it only helped a little.
Here's what we are working with:
What is the best way to achieve this? How will we know if the VPN tunnel was successfully connected?
On the SonicWALL, my NAT policy is:
Original Source: Any
Translated Source: [172.22.#.X/29]
Original Destination: [172.20.X.X/28 or 63.X.X.X/28]
Translated Destination: Original
Original Service: [VPN Service Group]
Translated Service: Original
My VPN configuration is set to be active for the translated source group to the original destination group.
Thanks in advance,
Overkill
Here's what we are working with:
- VPN uses IKE with a shared secret
- Phase 1 uses Main Mode/Group 2/3DES/MD5
- Phase 2 uses ESP/3DES/MD5 and does not have PFS enabled
- Local traffic originates from an address in 192.168.1.0/24
- If the destination is in 172.20.X.X/28 or 63.X.X.X/28, and is going over one of 5 specific ports, then it has to go over VPN Tunnel #1
- If the destination is in 172.25.X.X/28 or 74.X.X.X/28, and is going over one of 5 specific ports,then it has to go over VPN Tunnel #2
- Source IP for traffic over VPN Tunnel #1 must be translated to an address in 172.22.1.X/29
- Source IP for traffic over VPN Tunnel #2 must be translated to an address in 172.22.2.X/29
What is the best way to achieve this? How will we know if the VPN tunnel was successfully connected?
On the SonicWALL, my NAT policy is:
Original Source: Any
Translated Source: [172.22.#.X/29]
Original Destination: [172.20.X.X/28 or 63.X.X.X/28]
Translated Destination: Original
Original Service: [VPN Service Group]
Translated Service: Original
My VPN configuration is set to be active for the translated source group to the original destination group.
Thanks in advance,
Overkill