Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

routing traffic over an alternate gateway (fixed VPN with other plant) without TRAFFIC_INVALID

Since our old WatchGuard firewall died, I've set up a Sophos XG firewall as a matter of test.

Next to our gateway x.x.x.1 we've got a juniper SRX210 x.x.x.19 that functions as a VPN provider towards our motherfirm.

I've defined the routing towards the VLAN's as well as the zones of the VLAN's in the mother firm and created a rule that allows the LAN to the zones in the mother firm.

Pinging, tracert, etc all work fine.. I'm able to reach the servers at the other end.

But when I'm trying to connect to the iSeries with a Client Access client for instance, I'm not getting a connection.

All I see is that the traffic is denied and with the packet capture thingy, I receive a "Traffic_invalid" error.

If I add a manual route on a client, using the x.x.x.19 as default Gateway, the connection works, but printing from the iSeries to a local printer doesn't...

Can anybody advise please.

Thanks in advance for the effort

David.



This thread was automatically locked due to age.
Parents
  • Nice post and question.

    I think that you are suffering of asymmetric routing issue. The firewall does not manage the full connections so traffic is blocked and classified as spoofed.

    Is your configuration something like that?

    https://kb.cyberoam.com/default.asp?id=2017

    Tha Saching suggestion is great. When invalid traffic is logged, there could be a different reason why is classified as invalid. I had a similar issue few weeks ago with asymmetric routing.
    Let us know!

Reply
  • Nice post and question.

    I think that you are suffering of asymmetric routing issue. The firewall does not manage the full connections so traffic is blocked and classified as spoofed.

    Is your configuration something like that?

    https://kb.cyberoam.com/default.asp?id=2017

    Tha Saching suggestion is great. When invalid traffic is logged, there could be a different reason why is classified as invalid. I had a similar issue few weeks ago with asymmetric routing.
    Let us know!

Children
No Data