Hi there,
can someone please tell me where I can find the equivalent of Zyxel's Policy Route
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
Hi there,
can someone please tell me where I can find the equivalent of Zyxel's Policy Route
Hello Thierry MICHELS ,
Thank you for reaching out to the community, Please refer the following useful docs below:
1.) Sophos Firewall v19: How to Choose The Gateway For A Firewall Rule - Sophos Firewall: How to Choose The Gateway For A Firewall Rule v19
2.) SD-WAN policy routing - https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Routing/SDWANPolicyRouting/index.html
3.) Add an SD-WAN policy route - https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Routing/SDWANPolicyRouting/RoutingSDWANPolicyRouteAdd/index.html
With the help of the below command, you may verify the system-generated traffic SNAT details.
If no output which means no SNAT configured for system-generated traffic.
console> sh advanced-firewall
Below output will help on SNAT for system-generated traffic :
NAT policy for system originated traffic
---------------------
Destination Network Destination Netmask Interface SNAT IP
console>
Sophos XG Firewall: How to NAT Sophos Firewall generated traffic
https://support.sophos.com/support/s/article/KB-000035607?language=en_US
For delete, the command will be the same and in place of add, you may use del in the above KBA if you want to delete any existing system-generated NAT Rule.
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thank you for your answer
I tried to add under Remote Subnet the new VLANs and corrected the Firewall rule, but it doesn't work.
The LAN_arosa connect green and the VLAN_Arosa stay red.
Yup, so please check the logs on the remote site to narrow down the situation !
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Just one question:
Should the method I chose work?
If so, I think the problem is on the other side. And they need to check their configuration
Correct, please inform the team check on the remote site !
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Better asked question
Could I have 2 different Subnet in the remote subnet section
Of course, but whatever changes you make locally need to be reflected on the remote site !
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
as said the other side is a Zyxel
And on The Zyxel it is apparently not possible to define 2 subnets in the same site to site configuration
Alright, so this is the limitation of the remote site. Hence you'll have to continue using one subnet.
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello everybody
We found a solution for this Site to Site Problem
On the other side we have now 2 sidetoside configuration
On the local side the LAN_Crans Subnet
And for the local side as said befoe i have 2 Remote subnet in my site2site configuration
The connection is OK but I can't ping any device on the other side
But no Problem to ping with the firewall diagnostic ping
Can you perform the packet capture for the ping traffic - https://support.sophos.com/support/s/article/KB-000035761?language=en_US
And validate that the traffic over the IPsec is going from correct rule and IPsec0 interface ?
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thank you for your answer
But no packet receive fronm otherside 172.16.60.100
Firewall log:
And no capture with filter on otherside IP 172.16.60.100
Firewall ping
Thank you for your answer
But no packet receive fronm otherside 172.16.60.100
Firewall log:
And no capture with filter on otherside IP 172.16.60.100
Firewall ping
It looks like it is not detecting the traffic rule, can you create a separate firewall rules:
1.) LAN to VPN
2.) VPN to LAN
The traffic should go out of the IPsec0 interface !
Route Sophos Firewall-initiated traffic through an IPSec VPN tunnel
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thank you for your Answer
As said above it works with 1 tunnel on the Sophos (configured with 2 LAN) and 2 tunnels on the Zyxel.
The only problem is that ICMP does not pass