<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/147982/sophos-xgs-dnat-through-routed-vpn</link><description>Hello everyone, 
 I am attempting to redirect all requests made to 192.168.10.5 to 172.16.10.5. The VPN is working properly on both sides. 
 Sophos XGS: DNAT Through Routed VPN 
 Details: 
 #VPN Working 100% LOCAL-LAN: 192.168.10.0/24 (Sophos) REMOTE</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548643?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 12:47:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7ac4560a-b9c2-4957-a2c9-80a4ced589aa</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;Hello Naidu! Thank you. I&amp;#39;ll check it out later. I actually sorted that issue out after adding an alias like Toni mentioned.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548642?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 12:34:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e9ddaf09-4d66-4b1e-9db5-19cb74948d89</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;&lt;span&gt;Toni, I appreciated it! This one worked beautifully.Thanks!!&lt;/span&gt;&lt;/p&gt;
[quote userid="45582" url="~/sophos-xg-firewall/f/discussions/147982/sophos-xgs-dnat-through-routed-vpn/548618"]You can workaround this by putting the ALIAS IP of 192.168.10.5 on the LAN interface of the SFOS Firewall. Therefore we will reply to the ARP and then the connection will be routed.&amp;nbsp;[/quote]&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548639?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 11:42:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f531be92-0efd-4a0b-ad51-110401f1be7d</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;Or you can follow the suggestion given by me @&amp;nbsp;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/147974/force-outgoing-through-the-xfrm-interface/548601"&gt;RE: force outgoing through the xfrm interface&lt;/a&gt;&amp;nbsp; if that works.&lt;/p&gt;
&lt;p&gt;In the NAT rule of SFOS, either chose MASQ&amp;nbsp;if xfrm ip to be used or keep it as &amp;#39;Original&amp;#39; and configure 192.168.10.5 on the LAN port of SFOS.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548623?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 04:57:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f9069d31-2f7b-4b50-a33d-2df202be2883</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;Hi FMXio, you may consider WAF over RBVPN IPsec to achieve what you have described. You will have to use RBVPN with local and remote subnets as Any and Any on SFOS.&lt;/p&gt;
&lt;p&gt;&lt;a id="" href="https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/WebServerProtection/WAF/Rules/WAFSDWANRoutes/index.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/WebServerProtection/WAF/Rules/WAFSDWANRoutes/index.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548622?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 19:47:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8b4a2578-d190-49c0-b2a4-2958fe4343ca</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;Hey, I confess I thought about it, but with so many ideas at the same time, this one just disappeared. Now, after setting up this alias, the regular DNAT on the GUI interface is registering logs. That rule in the console, &amp;#39;set advanced-firewall sys-traffic-nat add destination 172.16.10.5 snatip 192.168.10.5&amp;#39;, didn&amp;#39;t work. Thanks!!!! I&amp;#39;ll keep finding a solution, and now I can capture packets and think better...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548620?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 18:20:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a2cecae4-fa6c-4c3a-b3f2-ab9b4e5c5f7f</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;THAT sounds like a solution - good point!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548618?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 18:17:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b106da21-3b07-4337-8c24-7b7bf8d3917a</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;True, i missed this:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Maybe PFsense is solving this differently, but what you have here is:&amp;nbsp;&lt;br /&gt;As there is no device to answer to this IP in your network, SFOS will also not do an ARP for it.&amp;nbsp;&lt;br /&gt;The client will reach out with an ARP to look for 192.168.10.5 - But SFOS is not responsible for it - So it will not answer and the SYN Paket will never be send.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You can workaround this by putting the ALIAS IP of 192.168.10.5 on the LAN interface of the SFOS Firewall. Therefore we will reply to the ARP and then the connection will be routed.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548616?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 17:43:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:83bd2d11-68e9-4c95-bee0-ab8e48788fc0</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;Thanks for your input, Philipp! Actually, I&amp;#39;m trying to redirect all the requests made from 192.168.10.0/24 to a server at 192.168.10.5 (Local-IPSec VPN) to another server (via IPSec VPN) at 172.16.10.5.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548615?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 17:22:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:47e17482-0097-4b08-a6c2-e06611d4e9e0</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;you are trying to reach a server at 192.168.10.5 /24 from the local LAN with 192.168.10.0 /24.&lt;/p&gt;
&lt;p&gt;This traffic will never hit the router (= gateway), because that traffic is inside your LAN and will stay there, no need to involve the gateway.&lt;/p&gt;
&lt;p&gt;So basically, you can configure very sophisticated rules and settings at the Sophos XGS, but that won&amp;#39;t work.&lt;/p&gt;
&lt;p&gt;Are you trying to avoid changing the Server-IP at the clients?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548613?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 16:24:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3ec79bf0-f5e3-493e-a3fc-1642c61b7690</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;&lt;span&gt;Thanks, LuCar, I&amp;#39;m reading up on &amp;#39;&lt;a href="/sophos-xg-firewall/f/recommended-reads/121408/sophos-firewall-routing-in-sophos-firewall-with-sd-wan-pbr" data-contentid="9be43e0eb60d4d9299c4dbdcd20486b5" data-contenttypeid="46448885d0e64133bbfbf0cd7b0fd6f7"&gt;Sophos Firewall: Routing in Sophos Firewall with SD-WAN PBR&lt;/a&gt;&amp;nbsp;&amp;#39; right now. Appreciate it!&amp;quot;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548611?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 16:14:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4a8a691b-28b8-484a-a779-a7ab0687cd3d</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;You should look into this:&amp;nbsp;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/121408/sophos-firewall-routing-in-sophos-firewall-with-sd-wan-pbr"&gt;Sophos Firewall: Routing in Sophos Firewall with SD-WAN PBR&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Basically: You need a NAT + Routing to get this running. Because NAT will only translate, but the firewall needs the route as well. Use static routing or SD-WAN Routing.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XGS: DNAT Through Routed VPN</title><link>https://community.sophos.com/thread/548608?ContentTypeID=1</link><pubDate>Wed, 13 Nov 2024 15:13:58 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:bf5f1753-61c2-4caa-b461-a18aaf82ead0</guid><dc:creator>FMXio</dc:creator><description>&lt;p&gt;I remember doing it in pfSense once, but I didn&amp;#39;t imagine it would be so hard in Sophos XGs.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0000ff;"&gt;Firmware - SFOS 20.0.2 MR-2-Build378&lt;/span&gt;&lt;/p&gt;
[quote user="FMXio"]&lt;p&gt;Hello everyone,&lt;/p&gt;
&lt;p&gt;I am attempting to redirect all requests made to 192.168.10.5 to 172.16.10.5. The VPN is working properly on both sides.&lt;/p&gt;
&lt;p&gt;Sophos XGS: DNAT Through Routed VPN&lt;/p&gt;
&lt;p&gt;Details:&lt;/p&gt;
&lt;p&gt;#VPN Working 100%&lt;br /&gt; LOCAL-LAN: 192.168.10.0/24 (Sophos)&lt;br /&gt; REMOTE-LAN: 172.16.10.0/24 (pfSense)&lt;/p&gt;
&lt;p&gt;#Servers&lt;br /&gt; Old Server: 192.168.10.5&lt;br /&gt; New Server: 172.16.10.5&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve set up a DNAT rule as follows:&lt;/p&gt;
&lt;p&gt;Source: 192.168.10.0/24&lt;br /&gt; Original Destination: 192.168.10.5&lt;br /&gt; Translated Source: Original &lt;br /&gt; Translated Destination: 172.16.10.5&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve also tried adding a DNAT rule via the console, both independently and in conjunction with the above rule, but with no success:&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;set advanced-firewall sys-traffic-nat add destination 172.16.10.5 snatip 192.168.10.5&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;[/quote]&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>