Proxy ID mismatch will
result in failure to establish the site-to-site IPSec VPN
tunnel. Therefore, configure identical Proxy IDs on both VPN
peers to establish the site-to-site IPSec VPN tunnel
successfully.
For example: In a site-to-site IPSec tunnel configuration, if one
VPN peer is configured with an IP address for a netmask of /32
and the remote VPN peer is configured with the same IP address
but with the different netmask of /16, it will result in failure
establishing the VPN tunnel.
Proxy ID for other firewall vendors are
referred to as the Access List or Access Control List
(ACL).
Proxy IDs in the VPN peers should be exact mirrors of each other
(that is, be opposite), but not match.
Example proxy ID configuration for VPN peers to establish an
IPSec VPN tunnel:
If VPN firewall 1 is configured with 192.0.2.0/24 as local ID and
192.0.2.25/24 as peer ID. Then, VPN firewall 2 must be
configured with 192.0.2.25/24 as local ID and 192.0.2.0/24 as
peer ID.
|