This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN Users through S2S and VLAN's

Hi all,

I have a problem with remote SSL VPN users that want to access locations that are connected with a S2S tunnel.
Followed the guide below but can't seem to get it working.

Sophos XG Firewall: How to configure access for SSL VPN remote users over an IPsec VPN

Site A (HQ) network interfaces are configured as LAG with multple VLAN's (All VLAN's work correctly)

Site A (HQ) is connected with S2S (IPsec) to multiple remote locations (all working correctly).

Site A (HQ) is configured for remote SSL VPN users and is working for the local subnet (VLAN 6).

Objects for the remote subnets are defined as IP network.

1st problem is that when i add more permitted network resources only the first one works (i cant access other VLAN's).
2nd problem is that remote users (SSL VPN) cant access the remote locations through the S2S tunnel.

I have configured a firewall rule with source/destination zones with VPN/LAN and put this on top of the list.
All VLAN's are member of the LAN zone.

Can someone provide me some guidance regarding this configuration?

Thanks in advance!

Best regards,

Dave



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out, and welcome to the Sophos Community! 

    Would it be possible for you to provide the screenshots of the firewall rules, site-to-site IPsec VPN, and SSL VPN connection profile? You may obscure the public IP address as well as personal detail for discretion. If possible, provide a network diagram.

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out, and welcome to the Sophos Community! 

    Would it be possible for you to provide the screenshots of the firewall rules, site-to-site IPsec VPN, and SSL VPN connection profile? You may obscure the public IP address as well as personal detail for discretion. If possible, provide a network diagram.

    Thanks,

Children
No Data