<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Traffic from VPN to VPN via Sophos XG</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/117267/traffic-from-vpn-to-vpn-via-sophos-xg</link><description>We&amp;#39;ve got a site to site VPN to a third party from our HQ site. We&amp;#39;ve also got a site to site VPN from a branch site to HQ. Both branch and HQ have Sophos XG firewalls. Is this something that should work, or are there limitations with traffic from one</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Traffic from VPN to VPN via Sophos XG</title><link>https://community.sophos.com/thread/423623?ContentTypeID=1</link><pubDate>Mon, 16 Dec 2019 21:35:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:49b8ab43-7f7c-43b2-bf5e-dcce0faa47b9</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;ersatcha,&lt;/p&gt;
&lt;p&gt;Check this KBA :&amp;nbsp;&lt;a href="/kb/en-us/123293"&gt;Sophos XG Firewall: How to create a hub and spoke IPsec VPN&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Traffic from VPN to VPN via Sophos XG</title><link>https://community.sophos.com/thread/423620?ContentTypeID=1</link><pubDate>Mon, 16 Dec 2019 21:18:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:51dabedc-2b2a-42cb-a8b4-3c7a0b339160</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi Ersatcha,&lt;/p&gt;
&lt;p&gt;It is possible to access Third Party Local network form BO location through existing IPsec Tunnels.&lt;/p&gt;
&lt;p&gt;In this example, I have used three local networks but in your case these networks might be different.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;1) Local on BO : 192.168.1.0/24&lt;/p&gt;
&lt;p&gt;2) Local on HO : 192.168.2.0/24&lt;/p&gt;
&lt;p&gt;3) Local on Third Party: 192.168.3.0/24&lt;/p&gt;
&lt;p&gt;On BO, update the tunnel to HO, add third party firewall&amp;#39;s local network in remote network of the connection.&lt;/p&gt;
&lt;p&gt;Remote Subnet:&lt;/p&gt;
&lt;p&gt;1)Local HO Subnet: 192.168.2.0/24&lt;br /&gt;2)Third Part Local Subnet: 192.168.3.0/24&lt;/p&gt;
&lt;p&gt;On HO firewall, you have to update both tunnels BO to HO and HO to third party.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;First update the tunnel between BO to HO and add local networks of third party.&lt;/p&gt;
&lt;p&gt;Local Subnet:&lt;/p&gt;
&lt;p&gt;1)Local HO Subnet: 192.168.2.0/24&lt;br /&gt;2)Third Part Local Subnet: 192.168.3.0/24&lt;/p&gt;
&lt;p&gt;Second, update the tunnel between HO to third party and add local network of BO.&lt;/p&gt;
&lt;p&gt;Local Subnet :&lt;/p&gt;
&lt;p&gt;1)Local HO Subnet: 192.168.1.0/24&lt;br /&gt;2)Local BO Subet: 192.168.2.0/24&lt;/p&gt;
&lt;p&gt;Note: Third Party firewall should configured with local network of BO in remote networks.&lt;/p&gt;
&lt;p&gt;You also requires VPN to VPN firewall rule to allow traffic from BO to third party firewall. You only need this rule on HO.&lt;/p&gt;
&lt;p&gt;Make sure that thre is no gateway route or have no NAT configured on IPSec tunnels.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Traffic from VPN to VPN via Sophos XG</title><link>https://community.sophos.com/thread/423602?ContentTypeID=1</link><pubDate>Mon, 16 Dec 2019 15:29:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4d0f30a6-e847-4c46-b955-9e02a5f68563</guid><dc:creator>Keyur</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/ersatcha"&gt;ersatcha&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;If you want to communicate between two VPN remote network, you required to have VPN to VPN firewall rule but you also required to add networks of BO and Thrid party network to HO VPN tunnel, same in the BO tunnel to communicate.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>