Description:

Unified Firewalls always use the IP address of the first active interface (usually eth0) as the sender address when using an internal service to communicate with a device connected via IKEv2. If the IP address assigned to the first active interface is not included in the VPN rules (e.g. the Internet connection is often set up on eth0), data cannot be sent over the VPN connection and communication is not possible.

In order to enable communications with the external device, the Unified Firewall must mask the packets intended for the external device with an IP address that is included in the VPN rules.

This article describes how to set up masking to the external device and so enable communications again.


Requirements:

Scenario:

Two Unified Firewalls are interconnected via an IKEv2 connection:



Procedure:

1) In the menu bar for the desktop objects, click on the icon to create a new network.

2) Modify the following parameters and then click Create:

3) In the menu bar for the desktop objects, click on the icon to create a new host.

4) Modify the following parameters and then click Create:

5) Change to the menu Desktop → Services → User-defined Services and click on the “+” icon to create a user-defined service.

6) Assign a descriptive name for the service and click on the "+” icon to assign ports and protocols to the service.

7) Use Port From and To to set the port or range of ports, and use Protocols to set the protocol. Then click OK.

For this example we are using UDP port 514 (syslog). You can assign multiple ports and various protocols to a service.

8) Click on Create.

9) On the desktop, click the network object created in step 2, select the “connection tool”, and click the host object created in step 4.

10) Use the “+” icon to add the user-defined service created in step 7.

11) Under the Options for the service, click None to access the advanced settings.

12) Modify the following parameters and then click OK:

13) Click on Create.

14) Finally, implement the changes by clicking Activate.