This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM IPSEC IPV4&IPV6 2 Tunnels same Subnet

Hello everybody,

 

I am a little confused about some things that we are gonna implement for our customers.

We have many UTMs running by customers in our datacenter based on virtual appliance and for each customer a functioning IPSEC VPN Tunnel over IPV4.

So far so good, now we are looking forward to find a possibility to offer a backup internet connection for our customers and we've received static IPV6 on both sides, in our

datacenter and to the customer via Telekom LTE. The fun is about to begin now, I am not sure if the Sophos UTM is providing such a protocol like dual stack for the WAN interface, if not

maybe we can add a secondary WAN interface and provisiong it with IPV6 but the real question is how is supposed to work the tunnel balancing ? First of all I thought it may be possible to add the IPV6 address to the existing IPV4 tunnel as a secondary gateway in the availability group but this is not gonna work I assume because of different IP protocols, then I thought I may have to had 2 tunnels, one tunnel over IPV4 and the second one over IPV6 and then eventually the second one with 1:1 NAT rule because of the same subnet so they can stay both online all time and by the time one is failing the second one should work as normally, but none of these possibilities seems to be working because for each of them remains an unsolved issue and I'm getting stucked over and over again.

Can someone tell me if it's technically possibile to achive something like this and how ? Have someone of you tried something like this before and has it eventually in the production already ?

Thank you in advance,

 

Arnold Hienz.



This thread was automatically locked due to age.
  • Hallo Arnold and welcome to the UTM Community!

    I'm a little confused - are these two, separate WAN connections or a single connection with both IPv4 and IPv6 addresses assigned?  The following two articles might help you: Auto-Failover IPsec VPN Connections and Sophos UTM multiple S2S IPsec VPN mit Failover – Tutorial (DE) by Michael Klehr.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Site A

    Sophos UTM

    WAN 1 IPV4

    WAN 2 IPV6

    Subnet IPV4

     

    Site B

    Sophos UTM

    WAN 1 IPV4

    WAN 2 IPV6

    Subnet IPV4

    I need LB for the vpn tunnels on both ends and a best practice to configure it. Both subnets are configured only with IPV4. Should I change the subnets to IPV6 or to provide the servers and clients ipv4 and ipv6 ?

     

    Thanks in advance,

    Arnold.

     

     

  • I don't think it's possible to do anything other than a modified version of Michael Klehr's approach where there are two tunnels based on IPv6-IPv6 and IPv4-IPv4 connections without using Interface Groups.  You should be able to tunnel IPv4 through an IPv6 connection.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA