Assuming Vigor3900 is in the Head Office and Vigor2960 is in the Branch Office, network Administrator created a VPN between the two offices and wants to make specific PC behind Vigor2960 to send all traffics to this VPN tunnel. While other PCs in Branch Office should access the Internet through Vigor2960. The example below will show you how to use the new Route Policy feature to achieve this purpose.
1. Add a new VPN profile: Go to VPN and Remote Access >> VPN Profiles, click Add and configure Basic Settings:
2. Configure GRE Settings for the VPN profile
3. Create a VPN Load Balance Pool: Go to VPN and Remote Access >> VPN Trunk Management >> Load Balance Pool, then click Add to create a new one.
4. Create a VPN Load Balance Rule: Go to VPN and Remote Access >> VPN Trunk Management >> Load Balance Rule, then click Add to create a new one.
NOTE: It is necessary to define which kind of traffic that needs to go through the VPN Trunk tunnel with VPN Load Balance Rule. Otherwise, traffic won't pass to the VPN Trunk tunnel.
1. Add a new VPN profile: Go to VPN and Remote Access >> VPN Profiles, click Add and configure Basic Settings:
2. Configure GRE Settings or the VPN profile:
3. Create a VPN Load Balance Pool: Go to VPN and Remote Access >> VPN Trunk Management >>Load Balance Pool, then click Add to create a new one.
4. Create a VPN Load Balance Rule: Go to VPN and Remote Access >> VPN Trunk Management >> Load Balance Rule, then click Add to create a new one.
5. After completing the configurations above, the VPN tunnel should be dialed up now. Go to VPN and Remote Access >> Connection Management for checking its status. Furthermore, ping to confirm if a local computer can get ping responses from a remote computer.
6. Create a Policy Rule to force a specific PC to send all the traffics to go through the VPN Trunk Tunnel: Go to Routing >> Policy Route, then click Add to create a new rule.
7. Using traceroute command tracert -d
to confirm if all the traffics from the specific PC with IP 192.168.1.10 are going through the VPN tunnel. From the traceroute result in the below screenshot, we can see the second node is Vigor3900's LAN IP, and that means the traffic to 8.8.8.8 is sending through the VPN tunnel
Published On:2016-05-25
Was this helpful?