This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC Site-to-Site can't access all remote networks

Hey all,

 

Can't seem to figure this out, I am sure it's something simple.

 

We have a NYC Office UTM 9 that has an IPSEC Site-to-site connection to a Texas office UTM 9.

----------------------------------------------------

NYC Office IPSEC Settings:

Local Networks:

NYC LAN 1 : 10.50.0.0/24

NYC LAN 2 : 10.80.0.0/24

NYC LAN 3 : 10.50.1.0/24

NYC LAN 4 (SSL VPN pool) : 10.242.2.0/24

Remote Gateway Name: TexasSophos

Remote Gateway settings:

Type: Initiate

Gateway : WAN address of the Texas Site

Preshared Key

VPN ID: IP Address

Remote Networks:

Texas Server LAN: 10.1.0.0/24

Texas Workstation LAN: 10.1.1.0/24

Texas Wifi LAN: 10.1.2.0/24

Texas Voice LAN: 10.1.3.0/24

----------------------------------------------

 

Texas Office IPSEC Settings

Local Networks:

Texas Server LAN: 10.1.0.0/24 

Texas Workstation LAN: 10.1.1.0/24

Texas Wifi LAN: 10.1.2.0/24

Texas Voice LAN: 10.1.3.0/24

Remote Gateway Name: NYCSophos

Remote Gateway settings:

Type: Respond

Preshared Key

Remote Networks:

NYC LAN 1 : 10.50.0.0/24

NYC LAN 2 : 10.80.0.0/24

NYC LAN 3 : 10.50.1.0/24

NYC LAN 4 (SSL VPN pool) : 10.242.2.0/24

-----------------------------------------------------------------------

 

I am able to establish all SAs. The issue is that from a workstation on the NYC Office LAN 1 (lets say 10.50.0.56) I can only ping/access hosts on the Texas Server Lan : 10.1.0.0/24 and cannot reach any other of the Texas Lans (Workstation, VOIP or Wifi)

All of the Texas Lans are actual physical interfaces.

I know I am missing something! Help guys please :)

 



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Christopher and welcome to the UTM Community!

    Rather than use manual "Any" firewall rules, I prefer to use 'Automatic firewall rules' in the IPsec Connections.  I would leave NAT-T enabled on both sides.

    Does doing #1 in Rulz give any insight into what is causing this mystery?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA