<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>force outgoing through the xfrm interface</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/147974/force-outgoing-through-the-xfrm-interface</link><description>Hello, everyone. 
 I created a DNAT rule. I receive the communication on the local interface at the SFW&amp;#39;s IP address on the LAN and translate it to another destination that is remote on the VPN. I force a SNAT with the SFW&amp;#39;s IP address that is assigned</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548822?ContentTypeID=1</link><pubDate>Tue, 19 Nov 2024 11:44:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cecdd4e1-adb8-4214-a448-da2529af1d4f</guid><dc:creator>Gib GoDesk</dc:creator><description>&lt;p&gt;Hello, everyone.&lt;/p&gt;
&lt;p&gt;Lucar and Sreenivasulu. Thank you for your support. Since it was a temporary migration solution, we rushed to migrate. However, after that, I calmly reviewed the articles written by Lucar again and I remembered some things and was able to apply them the way I wanted.&lt;/p&gt;
&lt;p&gt;I appreciate your help.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548633?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 10:14:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:84fdcb24-c0fa-45f3-b61a-ed85bdafb472</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;Hi @&lt;a href="/members/gib-godesk"&gt;&lt;span&gt;Gib GoDesk&lt;/span&gt;&lt;/a&gt;,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Pls try below configs (with reference to this setup):&amp;nbsp; client1---LAN---SFOS1&amp;lt;Initiator&amp;gt;-----wan---&amp;lt;Responder&amp;gt;SFOS2---LAN----client2&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;* &lt;strong&gt;Firewall rule on&amp;nbsp;SFOS1:&lt;/strong&gt; Source zone:LAN, source networks: Any, Destination zone: VPN, Destination networks: LAN port of SFOS1 (PortA)&lt;/p&gt;
&lt;p&gt;* Firewall rule on SFOS2: allow VPN to LAN zone&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;* &lt;b&gt;NAT rule on SFOS1:&amp;nbsp;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Original source: LAN n/w of SFOS1; Original destination: LAN port of SFOS1 (PortA)&lt;/p&gt;
&lt;p&gt;Translated source(SNAT): MASQ, Translated destination(DNAT): ip address 192.168.102.1&lt;/p&gt;
&lt;p&gt;Inbound interface: Any, Outbound interface: Any&lt;/p&gt;
&lt;p&gt;Original service or Translated service: as per your need&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;* Use static route on SFOS1 to reach far end LAN via xfrm1; similarly on SFOS2&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548601?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 12:40:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:757c39c1-a380-4ab8-8d94-f06e75f85d2d</guid><dc:creator>Gib GoDesk</dc:creator><description>&lt;p&gt;Thank you for your time.&lt;/p&gt;
&lt;p&gt;My criteria is set to: Static route, SD-WAN route, VPN route.&lt;br /&gt;I do not have any static routes configured.&lt;/p&gt;
&lt;p&gt;The SD-WAN rule to be used is the first one:&lt;br /&gt;&lt;br /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1731501217079v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;Lines 2 and 3 are other VPNs to other Networks and talk to other Sophos.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt; And finally, only public Internet addresses go out to the Internet.&lt;br /&gt;Rule Details:&lt;br /&gt;&lt;br /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1731501467413v2.png" alt=" " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;NAT RULES:&lt;br /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1731501635110v3.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548590?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 06:09:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0c15b9c9-8cf9-41e9-a834-23a0ee7f75c1</guid><dc:creator>Srisakthi S</dc:creator><description>&lt;p&gt;Any other selection criteria in your SD-WAN route configuration which is making traffic to 192.168.101.1 to bypass (a snapshot would help) ? Also what is the route precedence configured in your SFW?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548585?ContentTypeID=1</link><pubDate>Tue, 12 Nov 2024 19:06:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0298b6f8-fb2b-439c-9336-ebcbf26a21d0</guid><dc:creator>Gib GoDesk</dc:creator><description>&lt;p&gt;Thank you for your time, LuCar Toni.&lt;/p&gt;
&lt;p&gt;Yes, I&amp;#39;m considering updating it soon. I just got caught in the eye of the storm in the environment in question.&lt;/p&gt;
&lt;p&gt;I also appreciate your document. I&amp;#39;ve already used it and several other recommended reading articles that you created. You do a great job for the community.&lt;/p&gt;
&lt;p&gt;I only use SD-WAN and I reach the destination normally through it.&lt;/p&gt;
&lt;p&gt;The source configuration is set to any. The destination is at redfe 192.168.102.0/24. I only have one GW, which is the one linked to xfrm.&lt;/p&gt;
&lt;p&gt;I can&amp;#39;t mentally draw this packet flow when it is addressed to the IP directly from Sophos on the LAN interface, but if it doesn&amp;#39;t go to the SFW, when it passes through any IP on my LAN, DNAT and MASQ work.&lt;/p&gt;
&lt;p&gt;This is how it works:&lt;/p&gt;
&lt;p&gt;src: any -&amp;gt; dst: 192.168.101.10 (SERVER ON LAN) PORT: 8080&lt;br /&gt;translates to:&lt;br /&gt;src: 172.16.0.1 (XFRM IP\as object) -&amp;gt; dst: 192.168.102.10 (SERVER IP ON VPN) PORT: 8080&lt;/p&gt;
&lt;p&gt;This way when I look at the capture I see the correct communication, it enters and leaves through xfrm.&lt;/p&gt;
&lt;p&gt;When I do it for the IP that is in the SFW, it doesn&amp;#39;t work:&lt;/p&gt;
&lt;p&gt;src: any -&amp;gt; dst: 192.168.101.1 (SophosFW IP - PortA \ LAN) PORT: 8080&lt;br /&gt;translates to:&lt;/p&gt;
&lt;p&gt;src: 172.16.0.1 (XFRM IP\as object) -&amp;gt; dst: 192.168.102.10 (SERVER IP IN THE VPN) PORT: 8080&lt;/p&gt;
&lt;p&gt;This way it doesn&amp;#39;t work and when I look at the capture it is going out through the PortB internet interface or instead of going out through the xfrm interface.&lt;/p&gt;
&lt;p&gt;I know that this is traffic generated by the system itself and so I may need to use the settings to force SNAT. However, I understand that I don&amp;#39;t need to. My SDWAN rule is very comprehensive and I am using an IP directly used in the IPsec VPN connection interface.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: force outgoing through the xfrm interface</title><link>https://community.sophos.com/thread/548579?ContentTypeID=1</link><pubDate>Tue, 12 Nov 2024 17:35:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b9d3e954-bf9a-4af9-b1aa-72713654c748</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;You should consider to update your firewall.&lt;/p&gt;
&lt;p&gt;And please read this:&amp;nbsp;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/121408/sophos-firewall-routing-in-sophos-firewall-with-sd-wan-pbr"&gt;Sophos Firewall: Routing in Sophos Firewall with SD-WAN PBR&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The main takeaway: SFOS NAT will not change the routing decision. You still need routing + NAT to get your setup running.&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>