IPSec tunnel between RUTX50 and Prisma.
A couple of local networks 10.176.x.x, Remote networks 10.0.0.0/8 and 100.64.0.0/10.
Compatibility mode on, Passthrough configured.
The problem is that only one supernet works at a time. Either 10 or 100. Not from both at the same time.
swanctl -l shows only one remote subnet. The one that works.
Thanks for the warm welcome. Long time lurker here.
swanctl --list-sas | grep remote shows only one remote network, even though two remote subnets are configured on the IPSec tunnel .
Edit..
Well.. it showed both after I made a small change on the IPSec tunnel and clicked save and apply. But after reboot it only shows the first one… Same with local networks.. why is it doing that?
Based on your description, the IPSec tunnel is successfully established, however only one remote subnet appears to be active at a time, while the other is not being used.
To help us investigate further, could you please clarify the following:
What firmware version is currently installed on your RUTX50?
On the remote device (e.g., Prisma), do you see separate IPSec connections for each subnet, or only one active connection?
Does the issue persist if you configure separate IPSec tunnels for each subnet pair?
Are both subnets configured the same way on the remote (Prisma) side?
I would say so. When configured two IPSec tunnels on Teltonika with the only difference on remote subnets, only one gets established.
On the Prisma side, the only thing we configure for the tunnel is remote subnets, which in this case are 10.176.186.x. I have found an error there and have asked for correction.
For troubleshooting purposes, we will require more sensitive information from your end, such as the troubleshoot file, which may contain passwords, public IP addresses, serial numbers, and such. To avoid leaking this information, we have sent you a form to fill out, which you will receive in your e-mail inbox that you have registered your account with in the forums. In the Ticket ID field of the form, please enter the ID of this thread, which is 18910.
You are right to some degree. We have over 1000 sites. All using 10.x.
10.0.0.0/8 is overlapping everything, this is true, however, this set up works with other products. /10 is not overlapped as it is 100.x