This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trouble with masquerading

 I have a UTM 9.5 in the cloud. I connect to it with a L2TP over IPsec connection. I establish the connetion and visit some site to check my IP and it shows the IP of my UTM. If I drop the L2TP over IPsec connection and refresh it shows my work IP. 

So I assume that the masquerading works. 

 

Now if I connect through L2TP over IPsec to my UTM again and try to access my server's IDRAC interface which is in the same network as the UTM I see in the firewall logs of the UTM the IP of the VPN tunnel 10.xxx so it isn't being masqueraded. 

 

I checked the help page for masquerading and see:

Note – The source address is only translated if the packet leaves the gateway system via the specified interface. Note further that the new source address is always the current IP address of that interface (meaning that this address can be dynamic).

 

I need the access to my IDRAC to be seen as coming from my UTM's public WAN IP not the internal VPN IP. How can I fix this masquerading problem? Do you need more info or is my mistake already obvious?



This thread was automatically locked due to age.
Parents
  • If you're accessing your server through a different interface, then you need either a masq rule like 'VPN Pool (L2TP) -> Interface' for the entire "Interface (Network)" or a NAT rule.  The NAT could be as restrictive as 'SNAT : ovidiu (User Network) -> HTTPS -> IDRAC : from Interface (Address)'.

    Did that resolve your issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I already had an active masquerading rule for the Pool for everything leaving through WAN

  • That's not where the IDRAC is.  I'm not sure what the name of the interface is, but it's one that has an IP in the same subnet as the IDRAC server.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • That's not where the IDRAC is.  I'm not sure what the name of the interface is, but it's one that has an IP in the same subnet as the IDRAC server.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data