Hi there,
i currently have several IPSec site-to-site connections running on my Sophos UTM.
Recently we received the request to add many more and I do not want the UTM do all the work.
So my idea was that I could assign an additional IP address to my WAN interface and have all the new IPSec connections targeted on that new address.
Then, on the UTM I create a NAT rule to forward all IPSec-like traffic to a separate box which then takes care of the IPSec stuff for these new connections.
Unfortunately, this does not work. Packets to port 500 sent to the newly created address do not arrive at their target.
Could this be by design? Or is that supposed to work?
Best
Thomas
This thread was automatically locked due to age.