Hi *,
I'm attaching a sketch of a problem that I believe is related to policy based routing.
Whenever the mobile client tries to access the web server located in the DMZ behind the CPE using the port forwarding (DNAT) through the vpn appliance, traffic goes through.
However, since the mobile client's is connecting using a publicly routed ip address, the CPE (RB2011) forwards reply traffic using its default gateway instead of the vpn interface.
How can ensure that reply traffic leaves through interface ovpnc1 which is the one it initially arrived on?
Thanks in advance