This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM inside of another VPN Firewall - How do we make this work?

I wish to deploy our UTM inside of our existing ASA.  I have many sites connected IPSEC (IKEv2) to our ASA, and all traffic is tunneled from all remote sites to the ASA.  I wish for the UTM to perform its security functions (except Site to Site VPN) on all traffic, including the tunneled remote VPN sites and local LAN.  Diagrams below.  Sophos support tells us that they do not provide deployment assistance, but can help with configuring commands if we know what we want to do.  So, I ask you all:  how can I scan and protect all traffic from all sites on this spoke and hub setup.

Current State:

Future State:



This thread was automatically locked due to age.
Parents
  • Hi, Mark, and welcome to the UTM Community!

    I wouldn't do it the way you're trying to do it. The UTM is not like the ASAs.  Once it's set up by someone with experience, it will be extremely easy to administer and modify.  I've fixed more than one "messy" configuration designed by a very talented CCIE.

    You need to get a UTM installer with good experience and references.  If you don't have that confidence in your reseller, ask Sophos Sales for a recommendation.

    Just my two cents worth...

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Mark, and welcome to the UTM Community!

    I wouldn't do it the way you're trying to do it. The UTM is not like the ASAs.  Once it's set up by someone with experience, it will be extremely easy to administer and modify.  I've fixed more than one "messy" configuration designed by a very talented CCIE.

    You need to get a UTM installer with good experience and references.  If you don't have that confidence in your reseller, ask Sophos Sales for a recommendation.

    Just my two cents worth...

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data