This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec VPN packet not routed


we have configured an ipsec vpn between two sites

SITE A: is a cisco and imnitiate the connection

SITE B: is my utm an respond only

IKE: Auth PSK / Enc AES_CBC_256 / Hash HMAC_SHA1 / Lifetime 28800s / PFS MODP_2048
ESP: Enc AES_CBC_128 / Hash HMAC_SHA1 / Lifetime 3600s

and firewall rules are configured

The tunnel is up without problem but i if I do a tracert from my utm to the remote host I go via default route and not via tunnel

Can someone help me?

Best regards

This thread was automatically locked due to age.
  • Hello,

    Good day and thanks for reaching out to Sophos Community.

    Could you verify if the firewall rule for the VPN is on top the Lan->Wan rule? Could you also verify if VPN routes priority is higher than default/static routes? 

    Many thanks for your time and patience and thank you for choosing Sophos


    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hello,

    >>Could you verify if the firewall rule for the VPN is on top the Lan->Wan rule?

    The rule are on the top

    >>could you also verify if VPN routes priority is higher than default/static routes?

    sorry but on my old utm I don't know how I can see the VPN routes

    If I execute the "route" command the result is
    "       *      UH    0      0        0 eth2"

    where is the remote ip and the eth2 is the external interfaces

  • Hello thanks for this. Could you share your VPN configuration screenshot? Also, is this behavior happening to all end machines on the network? or just specific ones?

    Many thanks for your time and patience and thank you for choosing Sophos


    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • >>Also, is this behavior happening to all end machines....

    The vpn is only for one machine on the remote side and only one machine on the local side

    Automatic filrewall rules is unchecked but I've configured manualy the rules;

    another info; the output of command "ip route show table 220" is empty

    Best regards

  • Hello thanks for these details. does you manual configured rule have a vice-versa rule. E.g. HO network->BO Network and BO Network-> HO Network

    Could you try configuring an automatic rule and see if it will work.

    Many thanks for your time and patience and thank you for choosing Sophos.


    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hello, yes I have configured all necessary rules. I have tried also with automatic rules but the results is the same.

    If I do a tracert to the remote host my tracert is stopping to my external interface

    mailshield:/home/login # traceroute
    traceroute to (, 30 hops max, 40 byte packets using UDP
     1 (!)  3001.003 ms (H!)  2999.902 ms (H!)  2998.795 ms

    where is the remote host and is my External interface

    Best regards

  • Hello, yes I have configured all necessary rules. I have tried also with automatic rules but the results is the same.

    If I do a tracert to the remote host my tracert is stopping to my external interface

    mailshield:/home/login # traceroute
    traceroute to (, 30 hops max, 40 byte packets using UDP
     1 (!)  3001.003 ms (H!)  2999.902 ms (H!)  2998.795 ms

    where is the remote host and is my External interface

    Best regards
