Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG230 to RED-SDRED

Hello, good day, I hope you can help me, I have the following problem.
We have an XG230 that manages 10 RED15W, 1 RED50, and 3 SD-RED60, along with this firewall (XG230) a Fortinet brand firewall was implemented, but it is expected that both firewalls can see each other, that is, my computer that is on the Fortinet network at 192.168.1.x can reach the network of any RED (15W, 50, 60), and vice versa, that from any remote site with the RED I can reach my computer that is on the Fortinet network.
For this, an interface with the IP address 10.10.2.1 (LAN) is configured on the Fortinet
and in the same way, an interface with the IP address 10.10.2.254 (LAN) is configured on the Sophos
In the Sophos, I created the address. rule
source: lan-- fortinet network(10.10.2.0)
destination: lan-- remote sites(192.168.205.0....etc)
this rule does show me traffic and from my computer in the fortinet I can reach any computer that is in the RED(15w,50,60)
my problem is that from the remote sites I can't reach my computer in the fortinet, in the same way I have a rule that would be the opposite of the first one
source: lan-- remote sites(192.168.205.0....etc)
destination: lan-- fortinet network(10.10.2.0)
I already tried adding the hosts of each network instead of the networks that I created for each one and I still don't see traffic in this rule.
It should be noted that I have the networks configured as Standard divided and in the divided network I have added the Fortinet network that I created "10.10.2.0"
In the same way I left a network as standard unified and still I don't see traffic in the rule that I created only for this device, I have the networks in the LAN zone and only the unified one I put it in a different zone but still it doesn't show me traffic in the rule that I have only for this one.
Am I doing something wrong in a rule? Could you help me please



This thread was automatically locked due to age.
  • If you do not select a port, what happens then?

    Did you bridge port6 with another port?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • It gives me the same result, it does not give me a ping, I have not checked port 6 with another port, port 6 is where the connection is made to the fortinet that has the IP 10.10.2.254/255.255.255.0

    If I write my IP (192.168.1.231) in route search, it gives me the result that it is reached through router 10.10.2.1

  • I think your problem is at the Fortinet side.

    But please answer the other questions to go on.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.