Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Two Site Sophos Device MLPS Access Problem

Hi,

Two locations are connected with MPLS. Both locations have Sophos devices.

In both locations, the servers and PCs behind sophos can ping each other and access each other.

However, when we ping or trace the same ip addresses in the diagnostics section through sophos devices in both locations, sophos devices cannot access.

What am I missing?

Thanks...



This thread was automatically locked due to age.
Parents
  • Hi  Thank you for reaching out to the Sophos community team. What is the zone of MPLS if it is terminated on the Firewall at both ends? 

    What is the current route precede set for routing? ( Please navigate to Configure > Routing on Firewall Web admin and it will show the current route precende details).

    If you do the PING or TRACEROUTE from the Firewall > Diagnostics and around the same time if you do a Packet capture on the destination host IP on another tab are you seeing the correct interface in outdirection packets?

    If it is going out via the WAN Interface please validate the below section "Traffic between internal networks routed to the WAN interface" under "Routing and connection issues"; if that matches your current configuration situation:

    docs.sophos.com/.../index.html

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

Reply
  • Hi  Thank you for reaching out to the Sophos community team. What is the zone of MPLS if it is terminated on the Firewall at both ends? 

    What is the current route precede set for routing? ( Please navigate to Configure > Routing on Firewall Web admin and it will show the current route precende details).

    If you do the PING or TRACEROUTE from the Firewall > Diagnostics and around the same time if you do a Packet capture on the destination host IP on another tab are you seeing the correct interface in outdirection packets?

    If it is going out via the WAN Interface please validate the below section "Traffic between internal networks routed to the WAN interface" under "Routing and connection issues"; if that matches your current configuration situation:

    docs.sophos.com/.../index.html

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

Children
No Data