Routing for NAT and site-to-site VPN with RRAS


i'm trying set split-tunnel site-to-site vpn using rras server doing nat. right now, nat works: clients assigned ip address in 192.168.2.0/24 range, , able access internet through rras server.

i want add split-tunnel vpn packets destined 192.168.1.0/24 routed through vpn connection running on rras server, while continuing route other packets directly internet. thought setting static route vpn connection interface, 192.168.1.0 destination, , 255.255.255.0 mask, doesn't work.

the rras server able ping computers on 192.168.1.0 subnet well, none of other computers on 192.168.2.0 subnet can.

is right static route add?

i think 2 vms, 1 doing nat , 1 doing site-to-site vpn, i'd rather without vms if possible.

no, don't need 2 rras servers @ site. standard config rras server , has standard setup. @ other site? have rras server?

 site site vpn routing depends on routers @ both ends having ability route traffic "other" site through vpn tunnel.

setting routing @ 1 end pointless. routing two-way process. both routers must know how route "other" site. 


bill



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file