Routing for NAT and site-to-site VPN with RRAS
i'm trying set split-tunnel site-to-site vpn using rras server doing nat. right now, nat works: clients assigned ip address in 192.168.2.0/24
range, , able access internet through rras server.
i want add split-tunnel vpn packets destined 192.168.1.0/24
routed through vpn connection running on rras server, while continuing route other packets directly internet. thought setting static route vpn connection interface, 192.168.1.0
destination, , 255.255.255.0
mask, doesn't work.
the rras server able ping computers on 192.168.1.0
subnet well, none of other computers on 192.168.2.0
subnet can.
is right static route add?
i think 2 vms, 1 doing nat , 1 doing site-to-site vpn, i'd rather without vms if possible.
no, don't need 2 rras servers @ site. standard config rras server , has standard setup. @ other site? have rras server?
site site vpn routing depends on routers @ both ends having ability route traffic "other" site through vpn tunnel.
setting routing @ 1 end pointless. routing two-way process. both routers must know how route "other" site.
bill
Windows Server > Network Infrastructure Servers
Comments
Post a Comment