Do you have one or two MXs at site A? We have only 1- MX at cloud MX(Site A) Is it simply that when you connect to MX at site A via the client VPN, you do not have a route to site B? Yes we have routing. Becz MX has 2 ip subnet- 1) Default, 2) Client VPN. All the Clients(Site B) are connected through Default IP & we can connect through Client VPN Access. Example:- MX - Default : 20.X.X.X MX - Client VPN : 10.X.X.X Site 2 Site between Site A (Headoffice) to Site B (Client) 20.X.X.X to 192.168.X.X Now connecting: Branch Client VPN HO Server Clients 192.168.X.X 10.1.X.X - RDP 192.168.X.X Are the three subnets for client VPN, site A and site B distinct and not overlapping? I am not clear on this. what is three subnet? Does site B have site A as a default gateway, if not does the routing table have the client VPN IP subnet in it with the next hop as site A? While configuring Client's Firewall, we always mentioned both Default IP (20.X.X.X/24) & Client VPN(10.X.X.X/24) local subnets with gateway (30.X.X.X).
... View more