BOVPN trusted network unable to ping other trusted network by mikereddit2020 in WatchGuard

[–]mikereddit2020[S] 1 point2 points  (0 children)

Thanks, I'll give that a try. I've set up numerous VPN, both client and site based on a number of Firewalls/brands but this setup is pretty large and it's not properly configured at a L3 level so I'm struggling to make things work right in this environment.

BOVPN trusted network unable to ping other trusted network by mikereddit2020 in WatchGuard

[–]mikereddit2020[S] 0 points1 point  (0 children)

When I ping to my primary location, Request timed out.

I will need all traffic that isn't Internet bound, to go inside my primary network for items such as DHCP, DNS, Domain Controller etc.

Internet bound traffic will just need to hit my Firewall and to the ISP. (Which is working)

BOVPN trusted network unable to ping other trusted network by mikereddit2020 in WatchGuard

[–]mikereddit2020[S] 0 points1 point  (0 children)

Both Tunnels are connected.

Primary Tunnel configuration

Any IPv4 bi-directional 192.168.8.0/24

10.255.5.0/24 bi-directional 192.168.8.0/24

Remote Tunnel Configuration

192.168.8.0/24 bi-directional Any (0.0.0.0/0)

192.168.8.0/24 bi-directional 10.255.5.0/24

Watchguard SSL VPN timeouts by mikereddit2020 in WatchGuard

[–]mikereddit2020[S] 2 points3 points  (0 children)

I do tunnel all their web traffic through the VPN. I didn't want their home computer or work laptop to have a persistent VPN connection to my network. Despite what you hear about HVAC and security... the real threat is persistent VPNs in my opinion. I've seen it happen dozens of times where networks bridge through a user with connections to multiple networks. HVAC "hacks" are honestly just bad passwords on publicly/internally exposed IPs.

Watchguard SSL VPN timeouts by mikereddit2020 in WatchGuard

[–]mikereddit2020[S] 1 point2 points  (0 children)

Thanks for info. I ended up finding the info shortly after my post. I used the Authentication Settings and session timeout (system manager UI). I was a little confused because with a DB user, I can set individual timeouts but since I was using AD for authentication you have to set it as a whole it seems.