This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to configure ethX port on Sophos UTM to make it VPN only connection to the net?

Scenario:

I have NAS1 server. It is connecting to the i-net as other devices in the house.

I have ETH1 as a WAN port for the general internet use. NAS1 and all other devices are using standard network connection on sub 10.0.10X.

I wuld like to configure one of the UTM ports to connect only to a VPN server, like VyprVPN.

And disconnect fully when the VPN connection drops. I would like UTM to try and re-establish VPN connection when it drops.

I want my NAS2 server to be plugged in to that port, and make this server to connect to the i-net only over VPN.

I also would like NAS2 to be available on the 10.0.0.X network.

So UTM is connecting on ETH1 to the net as usual, can it also connect to the VPN only through ETH1 port, but tunnel the traffic to the ETH2 port, on which NAS2 is connected?

Does it make sense?

 

Can you please advise how that can be done?



This thread was automatically locked due to age.
Parents
  • "can it also connect to the VPN only through ETH1 port, but tunnel the traffic to the ETH2 port, on which NAS2 is connected?"

    That sounds like your solution, and I don't "see" what you mean.  Can you say this in another way, speaking more specifically about what you want to accomplish instead of describing the answer you're trying to make work?

    One thing that you need to know is that the UTM cannot be a "client" to a Remote Access VPN service - it can only be a server.  If the service offers a site-to-site connection, then the UTM can work with them.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • "can it also connect to the VPN only through ETH1 port, but tunnel the traffic to the ETH2 port, on which NAS2 is connected?"

    That sounds like your solution, and I don't "see" what you mean.  Can you say this in another way, speaking more specifically about what you want to accomplish instead of describing the answer you're trying to make work?

    One thing that you need to know is that the UTM cannot be a "client" to a Remote Access VPN service - it can only be a server.  If the service offers a site-to-site connection, then the UTM can work with them.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data