Building a site-to-site VPN using gateways managed by the same management server
In this section, we will examine two popular choices for star VPN topologies:
- To center only
- To center or through the center to other satellites, to Internet and other VPN targets
Star community – To center only
This VPN topology (selected by default) is used where independent access control is preferred at each satellite location. When implementing it in production, you need to do the following:
- Expand the basic access control policy we created earlier to contain specific rules.
- Enable HTTPS inspection on CPGW and configure the local HTTPS inspection policy.
- Either reuse the existing shared
APCL_URLF
layer or create a new one for this policy.
For our purposes in the lab, the basic policy, already in place, will suffice.
Regardless of which policy you are in, follow these steps:
- Click on VPN Communities [1] under Access Tools:
...