jerome_itable Lv2Posted 20 Feb 2024 17:08
  
Yes, it is possible to establish a tunnel between your two Sangfor NGFW sites even though they use dynamic public IP addresses. Both Sangfor VPN and IPSec can work with dynamic IPs, but with specific approaches:

1. Sangfor VPN:

    DDNS (Dynamic DNS): Utilize a Dynamic DNS service like No-IP or Dyn to automatically update a hostname with your current public IP address. Configure both Sangfor NGFWs to connect to the hostname instead of a static IP.
    WebAgent: Enable Sangfor WebAgent on both devices. It periodically communicates with a centralized server, updating its location information. Each NGFW can locate the other through the WebAgent server.

2. IPSec:

    NAT Traversal Techniques: Both NGFWs should employ NAT traversal techniques like NAT-T (encapsulation within UDP) or UDP Encapsulation to pass through Network Address Translation (NAT) devices.
    STUN (Session Traversal Utilities for NAT): Utilize STUN servers to help each NGFW discover its public IP address and establish the connection.

Considerations:

    Dynamic IP Updates: Ensure your chosen method promptly reflects dynamic IP changes. Delays can disrupt the tunnel.
    Security: Carefully configure security settings within the chosen method to maintain secure communication.
    Sangfor Documentation: Refer to Sangfor's official documentation for detailed configuration instructions specific to your model and version.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
1
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders