We'd love to hear about it! Click here to go to the product suggestion community
Have 2 sites connected with an IPSEC tunnel
192.168.1.0 - head office (SSL VPN 10.81.234.0)
10.1.10.0 - branch office (SSL VPN 10.81.235.0)
when a user connects via ssl vpn they can't communication to the other site. What do i have to add in order to accomplish this? please be specific I'm a noobie on sophos. I've seen articles on this, but everything seems to relate to the UTM9 not the XG.
I've tried adding the ssl vpn network in the ipsec connection local sub, and the remote sub on the other side, but still didn't work.
if you have created the SSL VPN for your VPN Users, make sure on the SSL VPN you also add the remote network.
For the IPSEC tunnel, make sure to include the IP/Subnet used by the VPN SSL. Go to VPN > Show VPN Settings > SSL VPN and take note of the address pool used.
In reply to lferrara:
I have tried that and still nothing.
In reply to Chris Trowbridge:
go to VPN > Remote Access SSL > Permitted Network put the other VPN remote site.
Also create a VPN to VPN allow firewall rule.
Already had the vpn remote site in the permitted network.
Firewall on head office (traffic is going over this now), but nothing is making it back
Branch office firewall
check from Firewall logs if packets are blocked. For example try RDP or any other service.
Nothing is blocked or appears to be dropped. The firewall rule allows it, but nothing shows on the destination firewall.
are you able from the SSL VPN client to ping any remote host?
If you issue a "traceroute x.x.x.x" command from the ssl vpn client, what is the result?
No can't ping anything over to the other site.
tracert looks to be going out of our gateway IP, then dies.
Any other suggestions?
so nobody can lend any other suggestion?
send me a PM.
After spending an hour with Chris,
we discovered that the routing table on the Head Quarter missed the correct network.
Issuing the command
system ipsec_route add net 10.1.10.0/255.255.255.0 tunnelname Office_Tunnel1
fixed the issue.
It should be a bug because the GUI should fill the routing table.
Yes this indeed fixed my issue. Can't thank you enough.
Hi everyone, i'm also having this issue. after adding the new route in the head office XG (wich was empty) nothing changed.