VPN Client IP Pool (IIP) Traffic Flow and Routing

VPN Client IP Pool (IIP) Traffic Flow and Routing

book

Article ID: CTX233720

calendar_today

Updated On:

Description

There are two examples each of communication with and without IIP, check the SRCIP / DSTIP in the packets to understand the key differences.
Familiarity with basic networking concepts like static routes / default routes / nating etc. is needed for proper understanding
For easier viewing, a ppt containing these slides is attached



User-added image


User-added image

User-added image


User-added image


User-added image

Key Points to note:

1. The IIP is first seen on the wire only when VPN traffic is exiting NetScaler Gateway towards the Destination the VPN Client wants to connect.
2. The exit interface of NetScaler Gateway for VPN Traffic is always determined by route lookup of the Destination the VPN Client wants to connect.
3. The Source IP of the packet exiting NetScaler Gateway
  - Will be the SNIP determined by route-lookup, If IIP is Disabled
  - Will be the IIP assigned to the VPN Client, If IIP is Enabled, regardless of the exit interface.

Issue/Introduction

This documents explains the traffic flow when Full VPN solution is deployed with and without Intranet IP pool (IIP) for VPN Clients. This can be used as reference to understand and implement routing of the IIP subnet in the network.