Disclaimer: Please contact Sophos Professional Services if you require assistance with your specific environment.
This article describes the steps on how to configure OSPF (Open Shortest Path First) routing over a Route-Based VPN (RBVPN) tunnel using the Sophos XG Firewall with SFOS version 18. This procedure will work between two Sophos XG Firewall devices as well as with a third-party network device as long as it supports RBVPN.
Note: This article does not provide in-depth information regarding OSPF, RBVPN, or firewall technologies.
Applies to the following Sophos products and versionsSophos XG Firewall version 18
Establish OSPF routing via RBVPN tunnel between the Head Office (HO) and the Branch Office (BO).
The configurations provided here are just an example. You can configure according to your organization's networks and requirements.
This scenario shows two OSPF over RBVPN connections with an equal cost. It shows the basic concept of the ECMP feature of OSPF and does not cover complex scenarios.
To achieve the scenario shown above, follow the same procedure on how to configure OSPF over RBVPN using the data shown in the network diagram above for each of the WAN connections and xfrm interfaces of the HO and BO. Once configured, there should be two RBVPN connections, two xfrm interfaces each for the HO and BO, the firewall rules can remain the same, and the LAN and xfrm networks should be participating in the OSPF process. Please see the screenshots below for the HO as an example.
Follow the same procedure in the Verification section.
The packet capture shows the two xfrm interfaces.