I have a slight issue, I am trying to ssh connect from inside the sophos utm box to a pptp vpn client.
I am able to ssh connect to clients that are on my internal network of 192.168.0.0
I am not able to ssh connect to clients that are on my pptp vpn network 10.242.1.0 from sophos utm itself, firewall log says default drop rule 60003.
I am able to ssh connect to clients that are on my pptp vpn network from the clients on the local network
I have passed 10.242.1.1 ---> port 2222 ----> 10.242.1.2 allow in the firewall.
I have tried different port numbers and tried adding as a dnat and checking log initial packet when watching real time log the initial packet comes up white but then is quickly dropped by 60003
when looking at the log I see
2018:07:29-02:19:04 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52858" dstport="2222" tcpflags="SYN" 2018:07:29-02:19:05 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52858" dstport="2222" tcpflags="SYN"
2018:07:29-02:19:07 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52858" dstport="2222" tcpflags="SYN"
2018:07:29-02:19:10 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52832" dstport="2222" tcpflags="SYN"
2018:07:29-02:19:11 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52858" dstport="2222" tcpflags="SYN"
2018:07:29-02:19:19 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="52858" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:33 shortsdedicated ulogd[4049]: id="2000" severity="info" sys="SecureNet" sub="packetfilter" name="Packet logged" action="log" fwrule="62054" outitf="ppp0" srcmac="**:**:**:00:51:5b"srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:33 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:34 shortsdedicated ulogd[4049]: id="2000" severity="info" sys="SecureNet" sub="packetfilter" name="Packet logged" action="log" fwrule="62054" outitf="ppp0" srcmac="**:**:**:00:4f:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:34 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:36 shortsdedicated ulogd[4049]: id="2000" severity="info" sys="SecureNet" sub="packetfilter" name="Packet logged" action="log" fwrule="62054" outitf="ppp0" srcmac="**:**:**:00:4f:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:36 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:40 shortsdedicated ulogd[4049]: id="2000" severity="info" sys="SecureNet" sub="packetfilter" name="Packet logged" action="log" fwrule="62054" outitf="ppp0" srcmac="**:**:**:00:4f:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:40 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:48 shortsdedicated ulogd[4049]: id="2000" severity="info" sys="SecureNet" sub="packetfilter" name="Packet logged" action="log" fwrule="62054" outitf="ppp0" srcmac="**:**:**:00:4f:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
2018:07:29-09:02:48 shortsdedicated ulogd[4049]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="ppp0" srcmac="**:**:**:00:51:5b" srcip="10.242.1.1" dstip="10.242.1.2" proto="6" length="56" tos="0x00" prec="0x00" ttl="64" srcport="59698" dstport="2222" tcpflags="SYN"
Thank you for any assistance.
This thread was automatically locked due to age.