skip site-to-site ipsec for RED Traffic

Hi,

I have a site-to-site vpn tunnel between two sophos firewalls Office1 (192.168.0.0) and Office2 (192.168.101.0/24). RED 20 is connected to another interface on Office2 firewall (192.168.102.0/24), configured as a LAN Interface. The users behind RED device cannot reach the remote subnet of office1 (192.168.0.0/24) because that subnet is included in sophos_2_sophos ipsec-tunnel.

How can I configure the office2 firewall to skip ipsec-tunnel for the traffic coming from the devices behind RED device and going to 192.168.0.0/24?

Thanks.



Edited TAGs
[edited by: Erick Jan at 2:20 AM (GMT -8) on 10 Feb 2025]