Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Access VPN (SSL) over IPSec

Hi all,

i have the following issue and hope that someone can give me a hint or two:

We're using a remote access connection (SSL VPN) to our Sophos XG. On the Sophos XG, we have an IPSec tunnel to another router (pfsense). Both work great.

Now, we're trying to access a host on the IPSec remote site via our SSL VPN connection. I already built some firewall rules, which allow access from our SSL network to the IPSec remote network on pfsense site, also i allowed the remote networks in VPN policy. I checked the routes given by the VPN on our clients and they seem ok (gateway is the VPN Sophos gateway).

However, it does not work and now we're a bit lost. When i try to ping a host on the remote site, i'm getting an answer from my ISP that the host cannot be reached. So it seems that, despite the client seems to have the correct route, it's not sending the echo over the SSL tunnel. Can someone give us a heads up what we missed or what has to be done to make this functioning?

Many thanks in advance!



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

    thank you for the help. I don't know if this article fits my case. For example, i think i can't create a general DNAT rule for the LAN port since not everything that comes this way from the remote network should be natted. But maybe i'm just misunderstanding this too. Can this article be used for a SSL VPN over IPSec connection? In the meantime, i tried to SNAT the VPN network to a single IP and an IP range from one of the IPSec local networks, which also didn't work.

  • To carry sslvpn ra traffic into the IPsec tunnel, 

    on SFOS, remote access vpn-->sslvpn --> global settings --> ipv4 addresses  - use this n/w (call this as virtual ip pool n/w) as part of 'Local subnet' of IPsec tunnel and 'Remote subnet' of IPsec tunnel config on PFsense; also adjust firewall rules to allow the sslvpn virtual ip pool n/w in the firewall rules on SFOS and PFsense.

  • Hi all, same problem, i cannot access from ssl vpn to the the remote ipsec tunnel