Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

sophos Firewall routing for Internal traffic and DNAT

Deployed sophos [SFOS 21.0.0 GA-Build169] on Azure and below is the detailed info

Sophos VM is deployed on VNet-Hub and peered with spoke VNet's

VNet-hub: 10.0.0.0/16
WAN (Port1): 10.0.1.4
LAN (Port 2): 10.0.2.4

Routed traffic between PC1 and PC2 through firewall using route tables.
VNet-Spoke1: 10.1.0.0/16
PC1: 10.1.0.4 (subnet: 10.1.0.0/24)
Route table:
route: 10.2.0.0/16 next hop: 10.0.2.4


VNet-Spoke2: 10.2.0.0/16
PC2: 10.2.0.4 (subnet: 10.2.0.0/24)
Route table:
route: 10.1.0.0/16 next hop: 10.0.2.4

Added static routes in Sophos
route 1:
Destination: 10.1.0.0/16
Gateway: 10.0.2.1
interface: Port 2

route 2:
Destination: 10.2.0.0/16
Gateway: 10.0.2.1
interface: Port 2


After the above static routes Dnat to 10.1.0.4 stopped working and it was working before.
How do i overcome this?



Edited
[edited by: syed munaz at 3:35 PM (GMT -8) on 11 Dec 2024]