Access Abnormal: Local Subnet Is Not Added

|
  • 190
  • 11

Issue Description

Sangfor VPN has been successfully established but can only access the LAN port network segment of the peer end. Other network segments on the intranet cannot be accessed. (This case screenshot is from the internal experimental environment)

For example, we have the following case:
Both devices are deploy in Bridge mode. The HQ has only one network segment of 192.168.20.0/24 (lane with the same network segment). The Branch has two network segments 192.168.30.0/24 (lan network segment), 172.168.30.0/24. As shown in the figure below, our VPN has been successfully established and can ping the lan port of the Branch but the other  segments cannot be pinged.

HQ VPN status:

Brach VPN status:

Ping the LAN port of the the branch device on HQ device:

On the HQ device, ping the 172.168.30.0/24 network segments of the Branch is unreachable:

Handling Process

On the HQ page console, we can see that the route can only see the route of the LAN network segment of the Branch. The routes of the 172.168.30.0/24  network segments are not seen.

At this point, we need to add the local subnet (non-LAN network segment) to the Branch device.  ps: The local subnet is the intranet segment of the local device. As shown in the following figure, we add the intranet segments to the local subnet.

After adding the local subnet at the Branch, the HQ ping test found that 172.168.30.0/24 are normal at this time.

You can also see that there are one more routes in the device routing table.


Root Cause

The local subnet was not added in the Branch device.

Solution

Add a local subnet in the Branch device.

Suggestions

When it is a multi-network segment, you need to add a local subnet. The purpose of adding a local subnet is to advertise the local subnet segment to the peer. Only the peer device can learn the route of the local network segment to ensure smooth data flow.

493225dfb1ec1d2a69.png (94.03 KB, Downloads: 0)

493225dfb1ec1d2a69.png

752875dfb1eca9fc6e.png (62.6 KB, Downloads: 0)

752875dfb1eca9fc6e.png

836255dfb1ed6e2e34.png (56.62 KB, Downloads: 0)

836255dfb1ed6e2e34.png

500395dfb1ee9751e3.png (62.6 KB, Downloads: 0)

500395dfb1ee9751e3.png
Bewok Lv3Posted 21 Jan 2020 16:45
  
thanks for article
Sangfor_Brando Lv5Posted 26 Feb 2020 09:09
  
Very helpful.
bramtorvalds Lv4Posted 06 Apr 2020 13:17
  
helpful and detailed article thanks for share
Faisal Posted 27 Aug 2020 07:34
  
Thank you very much for the information ...
Osama Muhammad Lv3Posted 27 Aug 2020 13:41
  
helpful and detailed article
Faisal Posted 14 Oct 2020 09:56
  
Nice article ...
Faisal Posted 25 Dec 2020 09:44
  
Great info ...
Faisal Posted 25 Dec 2020 09:44
  
Great info ...
Faisal Posted 31 Dec 2020 07:04
  
Very informative

I want to write a case
Doc ID: 2326
Author: Sangfor_Yong
Updated: 2019-12-20 16:08
Version: