Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN: Access to SSL Client side

There is a SSL VPN client connection to a Sophos XG Firewall. The Connection is fine. From the client side i get access to the XG Firewall local LAN. Now i need also access from XG Firewall local LAN to the Client LAN.

I have two Firewall Rules.

- VPN to LAN
- LAN to VPN

What else do I need.

Thank's  community.



This thread was automatically locked due to age.
Parents Reply Children
  • Hi  

    Based on the data you provided, I see you are using a bridge interface.  Is this correct?  Are you actually trying to bridge 2 networks together or are you just plugging in the ports assigned in the bridge?  I would recommend you remove the bridge interface and setup the LAN interface on the correct port.  Please note that doing this will remove the IP from the bridge interface, so you will need another IP on the XG to connect to.

    On another note, have you disabled windows firewall on the ssl vpn client side?  Windows firewall always blocks pings out of the box.  Also to note that if you are not using a full tunnel and the user on the other end has the same IP range on their LAN network as your LAN network, then this will cause problems.

    Try changing to a full tunnel on the XG SSL VPN and disabling windows firewall completely to see if it helps.  I also recommend having a rule VPN-LAN and LAN-VPN without routing or MASQ applied.  You can also try pinging the end system from the XG.  If there is no response to the XG, then the problem lies on the end client device.

    Thanks!

    KingChris
    Community Support | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link