Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote IPSEC VPN routing to internal LAN DEVICES

Hi Team,

I have created a network on layer 3 with a point to point connection from port 3 of my network to the layer 3, which ideally hold my internal network VLANS & devices. on port 3 i have the one IP, and on the switch i have another ip (point - point) connection. I created a static route from port 3 to the switch which works fines.

The above works very fine. 

I have tried to now to access above from a remote IPSEC which is a problem, for the last 5 days, tried reading around tried watching videos, but seems I am not getting there.

So below is my ipsec config

The internal zones are as below.

my fire wall rules are as per below.

my nat rule is per the below

When i Try to do a policy check i get everything green, 

When I do physical connection, the VPN establishes and connects, however I cant reach the ips behind the LAN port above, which is 10.254. ip series.

Kindly assist out.



This thread was automatically locked due to age.
  • Hello,

    any kind of network diagram would be very helpful. Since all these networks are internal, you don't need to hide anything like IP addresses and masks and routes.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Hello  

    1. Do you see the networks 10.254.*.* in route print output from the client machine?
    2. If the above is true, go to System -> Diagnostic -> Packet capture. Start the packet capture on destination IP and review whether the traffic routes via correct rule ID and NAT ID created or not.
    3. If it still fails, DM with the firewall access ID to review it further.

    Happy to help.

    Mayur Makvana
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question please use the 'Verify Answer' button.