@Spud wrote:
@DeaconZ wrote:
However, the Autokey IKE's bound to each tunnel interface cannot share the same Gateway or they bounce up and down.
This actually should work fine if you configure appropriate Proxy IDs on one or both tunnels.
Otherwise, sarahb's suggestion above (bind the tunnel interface to the Untrust zone) should also do what you need.
So,both are Netscreens (siteA is SSG550 & Site B is SSG20)
SiteA Config
Untrust IP = 1.1.1.1
Trust IP = 10.10.0.1
DMZ IP = 10.100.0.1
Gateway
SiteB-GW = 2.2.2.2
Autokey IKE
SiteB-Trust-VPN =10.20.0.1, bind tunnel.1, proxy ID local: 10.10.0.0/16 remote: 10.20.0.0/16 (I have multiple remote sites within this /16; they are all /22's)
SiteB-DMZ-VPN = 10.200.0.1, bind tunnel.1, proxy ID local: 10.100.0.0/22 remote: 10.200.0.0/24
*********************
SiteB Config
Untrust IP = 2.2.2.2
Trust IP = 10.20.0.1
DMZ IP = 10.200.0.1
Gateway
SiteA-GW = 1.1.1.1
Autokey IKE
SiteA-Trust-VPN =10.10.0.1, bind tunnel.1, proxy ID local: 10.20.0.0/22 remote: 10.10.0.0/16
SiteA-DMZ-VPN = 10.100.0.1, bind tunnel.1, proxy ID local: 10.200.0.0/24 remote: 10.100.0.0/22