Thursday, September 6, 2018

Possible to Create a IPSec Tunnel Between 10.10.0.0/23 and a 10.0.0.0/16 network ?

Hello. We are currently working to integrate a remote office into our main branch using a set of Palo Alto Firewalls. The remote office is currently setup with a pair of Layer 2 Ciscos into a PA-820 Firewall. The network we inherited was originally 10.0.0.0/8 but we changed it to 10.0.0.0/16 . We are trying to create a tunnel between that network of 10.0.0.0/16 and our network which is 10.10.0.0/23 and its failing. When the remote office does a traceroute to a remote ip of 10.10.0.144 we don' t see it hit the default gateway of 10.10.0.1 and it just times out as if the remote machine is on a local network. We also don't see it hit the firewall. Are we missing a major piece of network design here and banking too hard on the subnet masks? Thanks in advance!



No comments:

Post a Comment