This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT SSL Remote Access To Sophos Address

Hello Every body.

I have Sophos UTM SG310 with 4 internet connection.

I setup SSL remote Access listen on port 443(TCP) of sophos LAN Address and NAT from external Address to internal Address. User success connect to SSL Remote access but when one of internet interface down user cannot connect to SSL Remote Access.

Any body help me.

Sorry for my english. 



This thread was automatically locked due to age.
Parents
  • Chào Tran Ngoc Hien,

    It always helps to show pictures here regardless of your English - which isn't so bad!

    I will guess that you have selected a single interface in the SSL VPN setup.  You should change that to the "Any" network object.  Also, if you think you need a NAT rule, please show a picture of it.

    As DKKDG suggests, you can use one of the failover DNS services to have your FQDN resolve to an alternate IP when the primary IP is down.  An alternative is to show your folks how to edit their SSL VPN client config and save it with a new name.  For example, assume line 5 in C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config\trannh@wan1.yourdomain.com is:

    remote wan1.yourdomain.com 443

    Edit that file to change wan1 to wan2 in line 5 and save the modified file as C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config\trannh@wan2.yourdomain.com.  Now you can select either connection when you activate the SSL VPN Client.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Chào Tran Ngoc Hien,

    It always helps to show pictures here regardless of your English - which isn't so bad!

    I will guess that you have selected a single interface in the SSL VPN setup.  You should change that to the "Any" network object.  Also, if you think you need a NAT rule, please show a picture of it.

    As DKKDG suggests, you can use one of the failover DNS services to have your FQDN resolve to an alternate IP when the primary IP is down.  An alternative is to show your folks how to edit their SSL VPN client config and save it with a new name.  For example, assume line 5 in C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config\trannh@wan1.yourdomain.com is:

    remote wan1.yourdomain.com 443

    Edit that file to change wan1 to wan2 in line 5 and save the modified file as C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config\trannh@wan2.yourdomain.com.  Now you can select either connection when you activate the SSL VPN Client.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data