Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SOPHOS CENTRAL FIREWALL MANAGEMENT

Is it possible to create a NAT policy so that it uses the IP address of port #1 (LAN Zone) of the remote device as the MASQ address?

We have a client with around 28 remote offices. They are all connected by IPSEC site-to-site but only office LANs are allowed to connect.

That being said, all these offices have a wireless router (WIFI Zone) connected to Port #4 with a different network IP address than the LAN.

The VPN only knows about the LAN network (LAN Zone) to prevent mobiles from connecting to the main office networks.

To get these phones to connect we create a NAT rule so that it uses the LAN to reach the remote network. But there are many devices and configuring this manually is uphill.

This NAT only have the remote server and remote port with the MASQ using the Port#1 IP. 



This thread was automatically locked due to age.