This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing HTTP(S) traffic outside of Site to Site SSL VPN

Hi,

We've only had our SG430 a few months and for the most part have figured out how to do what we want it to do. The one thing I cannot figure out is this.

We have an externally hosted website that internal users need to access, this external site also needs to be able to read data from an internal SQL server. The thought is that we would set up a site to site SSL VPN on the firewall which would allow the external server access over the SQL Protocol to the SQL Server only (no other access to the internal network, no other protocols allowed to the SQL server). We set up the VPN connection and are waited for the external hosting company to configure their end. We then noticed that internal users were suddenly unable to access the webserver via HTTP. When we did a tracert the traffic stopped at the firewall. It wasn't until we disabled the VPN connection that access was restored to the website.

It seems like the SSL VPN routing is sending all traffic destined for the external webserver via the VPN connection (regardless if it's connected or waiting connection), how do I separate the traffic so only SQL goes over the VPN and the HTTP traffic goes via the external interface.

 

I thought about doing some sort of load balancing or multi path thing, but the VPN connections don't show as interfaces so I'm not sure how to fix this.

 

Thanks in advance for any help you might be able offer.

 

Regards,

 

Nick



This thread was automatically locked due to age.