Support Center > Search Results > SecureKnowledge Details
Certificate enrollment for Client to Site VPN over Site to Site VPN Tunnel fails Technical Level
Symptoms
  • Certificate enrollment for C2S over S2S fails
  • Traffic which returns from the Management Server over port 18264 is being forwarded to the actual IP address of the VPN Client machine in *clear* traffic instead of being encrypted and sent as ESP traffic.
Cause

Traffic on port 18264 is not being tagged as VPN traffic and is instead sent in "clear" because it is accepted by an implied rule.


Solution
Note: To view this solution you need to Sign In .