Can we establish VPN between Sonicwall if one side tunnel base and other side is Site to site
Manishkct
Newbie ✭
Best Answer
-
shiprasahu93 Moderator
Hello @Manishkct,
Welcome to SonicWall community.
Unfortunately, we cannot do it like that. When we use tunnel mode, the proposals are changed such that the network info is not recorded or sent in the VPN proposals.
If the other end is configured in site to site mode, it will need to match the network proposals to bring up the VPN tunnel. It is most likely to fail at that stage.
Is there a specific reason why this set up is necessary?
Thanks!
Shipra Sahu
Technical Support Advisor, Premier Services
5
Answers
Is there any way to do it
@Manishkct,
In that case, I would suggest using NAT over VPN. Even if you use the tunnel mode, the remote networks will be specified on the route policy and the firewall will be confused on which VPN to use for that destination network.
Please take a look at the KB articles below
I hope this helps.
Thanks!
Shipra Sahu
Technical Support Advisor, Premier Services
Thanks Shipra for the respond.
Here is my concern, Please let me know how I can proceed it further.
Please let me know how we can do this and 1st site-to-site should not impact.
Appreciated your help.
@Manishkct,
You can use the IPs like 192.168.2.10, 192.168.2.20 instead of 192.168.1.10, 192.168.1.20 respectively in the VPN tunnel that you set up on this end. On the remote side, 192.168.2.10, 192.168.2.20 would need to be translated back to 192.168.1.10, 192.168.1.20 respectively.
So, when you need to access 192.168.1.10, 192.168.1.20 from this site, you would use 192.168.2.10, 192.168.2.20 respectively instead. Once it reaches the remote end, they will be translated to the right IP addresses and there would be no overlap.
You can choose any other subnet that does not overlap with the local networks or other remote networks instead of 192.168.2.x. I have used that as an example.
I hope this helps.
Thanks!
Shipra Sahu
Technical Support Advisor, Premier Services