This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ssl vpn to dnat

hi

i have currently a dnat for a local pbx in sophos xg firewall

from the wan, everything works fine. but when a user connects to vpn, he cannot reach the public ip, thus can't use the pbx. this public ip seats in the same FW as the vpn, same system.

what's the correct way to create nat/policy so that a user connected to the vpn, will still be able to transparently connect to the public ip even when connected to the vpn?

thank you



This thread was automatically locked due to age.
Parents Reply
  • thank you

    the dnat rule is "any" in the source zone

    some users with a policy of "use as default gateway" and some don't. none of them can reach the pbx via vpn

    for example, when i run a trace while connected to the vpn (trace of the public ip), it goes through the sslvpn and not by local gateway

Children