This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN bidirectionality

Hi,  

 

I've configured VPN remote access. I can access the remote computers through the VPN, but I want the remote computers to be capable of accessing the computers that establish the VPN. I have a server on the remote site that must automatically place content on a share of the computer that establishes the connection.  It would be fine if it could find it by name, but it can be by IP if by name is not possible. 

I've seen that with PPTP it is possible to assign permanently an IP address when the connection is made, and it can even be an IP address from the same network of the remote site. But being  aware of PPTP secutity flaws, I would like to implement the solution with L2TP with IPSEC. 

 

Best regards, 



This thread was automatically locked due to age.
  • Hi Marco,

    this is also possible with L2TP and IPSEC. From Online Help:

    Note – The static remote access IP can only be used for remote access through PPTP, L2TP, and IPsec. It cannot be used, however, for remote access through SSL.

    Regards mod

  • There is a "trick" that can be used with SSL VPN remote access...  When the User mteixeira logs in to the SSL VPN, the object "mteixeira (User Network)" is populated with the IP assigned to the connection.  If you create an Additional Address "Internal [mteixeira] (Address)," you then can use a NAT rule like:

    DNAT : {server} -> Any -> Internal [mteixeira] (Address) : to mteixeira (User Network)

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA