Friday, July 12, 2019

Connect two branch locations over HQ using IPSec

Hello, r/networking

Hopefully the title makes sense what I am trying to do.

I have 3 Mikrotiks (I can also use 3 Cisco's ISR's as well) trying to configure a topology which replicates this:

PaloAlto how to connect two branch locations over HQ

The basic idea is to create two VPN tunnels: Site A <--vpn--> Site B <--vpn--> Site C; and have traffic going from Site A to Site C go over Site B (while being encrypted).

I have successfully created both tunnels between Site B and Site A and between Site B and Site C. The problem I have is that, when I try to add traffic from Site A going to Site C (and vice versa) in the IPsec configuration, I loose connectivity between both sides.

Also, there is no NAT between the local and "WAN" interface.

Any idea how to proceed? Googleing is starting to fail me at this point



No comments:

Post a Comment