Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

All traffic of some IP's branch office through SSL VPN tunnel

Hi,

I have 2 Sophos XG with an SSL site-to-site VPN.
I'm trying to pass all traffic from for a small number of IP (from 172.16.30.50 to 172.16.30.100) of the branch office Sophos XG, through VPN tunnel so they can present themself as a Home Office Sophos XG

I follow the hints in this KB guide, with no luck:

https://community.sophos.com/kb/en-us/123261

Can you help me on this???

Thanks in advance...



This thread was automatically locked due to age.
Parents Reply
  • Hi,

    Just did.

    Seems traffic don't pass-through at all.

    This is rules on branch office, from top to bottom:

    - Deny Rule [from LAN/rangeIP-> WAN/Any - Any Service]
    - Default Rule [from LAN/Any-> Wan/Any - Any Service]
    - Outbound IPSec [from LAN/LanNetwork-> VPN/RemoteNetwork - Any Service]
    - InBound IPSec [from VPN/RemoteNetwork-> LAN/LanNetwork -Any Service]

    This is the rules in Home Office, from top to bottom:

    - Default Rule [from VPN LAN/Anyhost-> Wan/Anyhost - Any Service]
    - InBoud IPSec [from VPN/RemoteNetwork-> LAN/LanNetwork -Any Service]
    - OutBound IPSec [from LAN/LanNetwork-> VPN/RemoteNetwork - Any Service]
    - IPsec Remote NAT [from VPN, LAN, Anyhost -> VPN, LAN, Anyhost  - Any Service] With Rewrite source address MASQ
    - VPN for remote users [from VN, Remote SSL VPN, -> LAN, Any Host - Any Service] With Rewrite source address MASQ and Match known users


    The tunnel is up and running.

     

Children