This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Restricting traffic between site to site vpn

I have set up a vpn between us and a client, and have created an interface and subnet specifically for this, with our main office network being on a different interface and subnet (Local)

1 .Local net 192.168.0.x

2. Separate Network for devices to talk to client 192.168.30.x

3. client network via VPN 10.x.x.x

This is working ok, but have just realised i can access a http address of a machine on the clients network (3) from our Local(1) network, when I assumed it would be blocked as the vpn created auto rules are to allow any traffic between (2) and (3).

I have even created a drop all rule from (1) to (3) in firewall rules but is still accessible via http, but not ping?

bit concerned that I maybe opening up our main network to traffic from the client.



This thread was automatically locked due to age.
Parents
  • Hello Jon,

    Thank you for contacting the Sophos Community!

    If you selected to create an Automatic Firewall when you created the tunnel, this will take precedence over your manually created firewall rules.

    I would recommend you remove the Automatic Firewall rule, and set one for the traffic going there, and another for the traffic initiated from the other end with the service you want to allow, by default the Service is set to ANY.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello Jon,

    Thank you for contacting the Sophos Community!

    If you selected to create an Automatic Firewall when you created the tunnel, this will take precedence over your manually created firewall rules.

    I would recommend you remove the Automatic Firewall rule, and set one for the traffic going there, and another for the traffic initiated from the other end with the service you want to allow, by default the Service is set to ANY.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children