SD-WAN

 View Only
  • 1.  Issue with branch sites traffic into passthrough tunnel on DC

    Posted Jun 21, 2023 08:48 AM

    Hi everyone,

    I opened already an case with Silverpeak, but maybe I look over something and find the solution faster here. :)
    First a short situation draw.
    I have 1 silverpeak appliance that has a passthrough tunnel to one of the remote customers which is not a silverpeak device.

    Configured with a VTI which is working fine and up.
    I can ping and send traffic from the appliance to the other side and receive it also.

    I created routes on this appliance for subnets of the other side and used the VTI address of the other side as next hop.
    This route has been advertised to all my other silverpeak appliances. 

    Verified and tested.
    So far so good.

    Issue is that my branches can not reach the remote customer.

    What I see in the flows is that the traffic arrives on the right appliance, comes into the passthrough tunnel of the customer.
    Customer sends a reply and then it stops.
    So I see no return traffic in the flows.

    If I do packet capture of the passthrough I see the reply arriving, but the silverpeak appliance ignores it for some reason.
    There isn't any duplicated IP range or whatever. Also no drops or firewall rejected found in the flows.

    Anyone else had this issue, or know where I must look for the solution?



  • 2.  RE: Issue with branch sites traffic into passthrough tunnel on DC
    Best Answer

    Posted Jun 21, 2023 05:06 PM


    What did you set as interface type for the VTI ?
    It must be WAN.





  • 3.  RE: Issue with branch sites traffic into passthrough tunnel on DC

    Posted Jun 22, 2023 06:43 AM

    Hi Nicolas,

    This was the thing I forgot / didn't know.

    Was type LAN. Tested and works as a charm.

    Reason why posting on this forum helps. :)

    Thanks a lot!