Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Route specific website via IPSEC Site to Site VPN

I have a Sophos XG firewall in India as well as a US branch. We cant reach some US medical websites from India. How do I send specific website traffic from India network through the US firewall?

The websites can be reached from the US branch. How do I redirect specific website traffic spoofing US WAN IP to reach those websites? I cant provide SSL VPN \ 3rd party chrome VPN for all users to access those sites.

I can set up a site to site VPN by following the Sophos knowledgebase. But I need help to achieve the above requirements.



This thread was automatically locked due to age.
Parents
  • Inspace,

    make sure that the website is resolved via an internal IP and not by the WAN IP from the India office. If you are using XG as dns, simply create a record with the yxzmedical.com --> internal IP of the US internal webserver.

  • I am able to resolve the IP of those websites. The website is working fine if I use a chrome proxy. Those websites are blocked for other countries on purpose. 

     

    If I install a proxy on all user desktop, Then there is no purpose of using a firewall to block unproductive sites & apps. Right now I need India branch users to access those websites impersonating US WAN IP.

Reply
  • I am able to resolve the IP of those websites. The website is working fine if I use a chrome proxy. Those websites are blocked for other countries on purpose. 

     

    If I install a proxy on all user desktop, Then there is no purpose of using a firewall to block unproductive sites & apps. Right now I need India branch users to access those websites impersonating US WAN IP.

Children
  • Inspace,

    sorry but I do not understand. Is the website the one published on US network?

  • No. The website xyzmedical.com is public like google.com. But can be accessed only within the US country. So India branch users cant access the site without 3rd party proxy

  • So, there's a medical website that's only available on the US, and you want to route all connections to that website from the XG in India to the XG in the US?

    Both XG are connected through an IPsec Tunnel. So the first thing is to create a new gateway of the US XG IP on the India XG.

    Then;

     

    On v18 you can create a SD-WAN Policy in the India XG, with the service (HTTP+HTTPS) and the destination (FQDN), and use the XG in the US as the primary Gateway.

    On v17.5 you could do the same, but instead of using the SD-WAN like in v18, you would need to create a Firewall Rule, with the Users/Source and the Destination + Services (As above), and again use the XG in the US as the gateway. (I'm not sure about v17.5 method.)


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 EAP @ Home

    Sophos ZTNA (KVM) @ Home

  • Once site to site VPN is established. will the primary gateway drop-down display US WAN link?

    will try and update you.

  • Now it is clear.

    Implement what suggested. This will work only if the website is outside the remote network reachable via the S2S VPN. Otherwise you need to create a loopback NAT on XG based in US.

    Regards

  • You need to create the gateway manually, you will only do this process once.

    Login in the India XG and on the left panel go to Routing, then Gateways.

    Add A new Gateway, put the Name as something relevant, and then on the Gateway IP you put the IP of the US XG over the IPsec connection established, you can also do health checks with ping if necessary. (Leave Interface as None.)

    Then you will be able to use the US XG as Gateway for anything necessary.

     

    Example:


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 EAP @ Home

    Sophos ZTNA (KVM) @ Home