Re: vpn-1 and home network If you can't turn off Hub Mode then whenever you connect to the VPN then all of the traffic from the client is sent down the VPN Tunnel. This is exactly what Hub Mode is supposed to do. If you want to be able to connect to resources inside your corporate network and outside at the same time, then you will have too turn off Hub Mode. If you are running NGX software on the gateway then you can define a seperate Remote Access Encryption Domain to the Site-to-Site. This is what I did for a customer who wanted what you want. The Remote Access Enc Dom covered the local networks and also the networks behind other site-to-site VPN tunnels along with anywhere connected via corporate network, ie MPLS, lease lines etc. Hub Mode can then be turned off and providing your home net and corporate network don't have the same IP range then can access your home net and corporate network at the same time. |