This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

s2s Ipsec using public ips?

 need to setup a site to site ipsec vpn with a partner company, they provided me the standard connection sheet but both the firewall endpoint and internal access are both public ips

Example

Customer

Firewall Address   147.118.246.5 (PUBLIC IP)

Internal Server Access :  147.118.246.50 port 666 (PUBLIC IP)

My Sophos UTM 9

Firewall address 200.10.10.5 (PUBLIC IP)

Internal Server Access : 10.10.10.50 port 666 (PRIVATE IP)

The partner is expecting me to provide a public ip as well for phase 2, what Ip should I provide?

How should I configure the tunnel ? 

Any help will be apreciated

Thanks

Gaston



This thread was automatically locked due to age.
  • Thanks Bob.

     

    I will share the real production ip info, at this point I need to make this work.

     

    Here is my Ipsec with them

     

    The public ip set as local network is 216.191.86.245 which is an ip address I own, it's not in use and not set as additional address in the firewall as suggested.

     

    Here is the SNAT

    For traffic from = WLAB-9 is my internal server ( 10.10.10.116) 

    Using Service ( 1414)

    Going to = 147.118.246.42 (Internal Partner but using public ip)

    Change Source to : 216.191.86.245 which is the same ip set as local network

    When I try to telnet from WLAB-9 ( 10.10.10.116) to the remote server 147.118.246.42 on port 1414 I see the following

     

    Now, I was expecting the DNAT to show me source change, but I am not sure that's should be the case.

     

    What would be the best way for me to see if the conversion is happening to 216.191.86.245 , also to see if traffic is leaving the firewall?

     

    Thank you guys for all your help

     

    Gaston

  • Remote Gateway picture?  Everything else looks like the problem is on the other end.

    To see traffic inside an IPsec tunnel, you must first know the REF_ of the IPsec Connection:

    cc get_object_by_name 'ipsec_connection' 'site_to_site' 'CB-???? Dev s2s Ipsec'|grep 'ref'

    Assume that gave you REF_Cb????DevS2sIpsec

    espdump -n --conn REF_Cb????DevS2sIpsec -vv

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob.

    Attached the remote gateway

    The gateways is 170.41.166.50

    Remote Host is 147.118.246.42

     

     

    I believe that is also correct as the tunnel is healthy... I will follow up with the other end.

     

    Thanks

     

    Gaston