Hi,
I have a very strange behaviour with our and one of our customer's UTMs. Historically we have more than one gateway in our LAN (yes... I know, we are working on a better network design). One gateway (.101) is responsible for the VPN connections to our customers (Cisco ASA 5510), the other one (.100, Sophos SG230) is our default gateway and has static routes for the remote networks to be redirected to the ASA.
We have a monitoring system in our LAN, that - amongst other things - checks the UTM Management ports of our customers WAN interfaces. There don't exist any static or dynamic routes for 4444, so the traffic normally goes over our UTM and her VDSL modem and everything is fine. Default gateway of the monitoring system is the .100 and no route entries exist.
So, after 2 or 3 weeks the UTM management port is going down for only one customer. If I check his WebAdmin I can see 4444 connections coming from our ASA. Since the checks normally go out over our UTM only that WAN IP address is allowed to connect to the customer's WebAdmin.
If I traceroute the IP from our monitoring system the traffic is leaving our network over the 2nd gateway. If I traceroute the same from our UTM, it leaves the network over the normal VDSL connection.
I know, asynchronous routing is a bit... but how can something like this happen? The VPN gateway uses different IPs for NAT (that one hits the customer's UTM when my "problem" happens) and VPN. Our UTM is only routing the remote networks, not the external IPs to the second gateway.
This thread was automatically locked due to age.