This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem with my SOPHOS IPSec Site to Site VPN Tunnels

Hi to all SOPHOS Support,

Good day.

I am having a very weird issue with my VPN connection. From Site A (SOPHOS) to Site B (FORTINET) my VPN is in green mode and working. The problem all my PC from SITE B can ping and connect to SITE A. But SITE A computers cannot connect to SITE B. They cannot do ping, cannot see shared folders. But the VPN connection in VPN is in color green. I tried to restart the VPN still the same. Does anyone have any idea on how to fix this problem? 

I tried to disable firewall policies still no go.

Any help will be greatly appreciated.

Thanks

Rodney



This thread was automatically locked due to age.
Parents
  • Hello Rodney,

    Thank you for contacting the Sophos Community.

    I would recommend you to check if the packets destined to Site B are going to the IPsec tunnel using the GUI Packet Capture.

    Also make sure you don't have overlapping networks on your end that match the Remote Subnets of Site B.

    Try also checking if you have any conflicting static route or SD-WAN and if the VPN routes have precedence. (For this last step you need to SSH into the XG and press 5>4 in the Main Menu to land in the Console)

    console> system route_precedence show

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi emmosophos,

    Thanks for the swift response. I check thru SSH and here is the result.

    I think I have conflicting SDWAN rules with VPN. How can I change the precedence making VPN routes number 1 then SDWAN as second option?

    Thanks

    Rodney

Reply Children