How to set up a VPN behind an existing firewall

Description

This article tells you how to set up a VPN behind an existing firewall. Once you are going to set up a VPN with one site behind an existing firewall or third party appliance, you can use routed mode and add a static route down stream on the upstream router?

Image

However, if you cannot access to and configure that third party appliance, to set up an existing firewall is not as complicated as you think.

 

 

Resolution

To set up the VPN behind an existing firewall, you can use site to site VPN with aggressive mode and it's not necessary to do any NAT tranversal.

In this case, for site SAN, you can configure the site as below.

Image

For site LOS, you can configure the site as following picture.

Image

Once the configurations are done, the VPN Tunnel will be up on both sides.

Image

Image

Related Articles

  • How to use www.pkitools.net for Resigning the DPI SSL Client Certificate.
    Read More
  • SSLVPN authentication with SAML and Google Workspace
    Read More
  • Certificate error when accessing certain websites when Client DPI-SSL is Enabled
    Read More
not finding your answers?