This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Three way site2site VPN

Hi all together,

first of all: I am pretty new to Sophos UTMs so I might lack some basics you would otherwise expect me to have.

Currently I am planning a three-way site2site VPN connection.
Later on this will be expanded to connect 16 different locations all connecting to the HQ.
We decided against RED devices because all locations need to be as independent as possible.

Furthermore all locations share the same LAN subnet (172.17.0.0).

This leads directly to site2site VPN configurations between mostly SG115 firewalls.

At the moment I get the error:
cannot route -- route already in use for "X_location a to location b"
Bot sides are behind a router and NATed, but adding the local IP as VLAN-ID solved that as it seems.

From other posts I guess my failure lies within the assigned IP-Adresses on the interfaces.
LAN-Interface: 172.17.2.23/255.255.0.0
WAN-Interface: 172.17.2.22/255.255.0.0

So I will change the IP on the wan interface.
The question is: In wich way?

Will it work when all  locations (3 for now) have the same subnet on the WAN-Interface?
Example:

Location A
LAN-Interface: 172.17.2.23/255.255.0.0
WAN-Interface: 172.18.2.23/255.255.255.0

Location B
LAN-Interface: 172.17.2.24/255.255.0.0
WAN-Interface: 172.18.2.24/255.255.255.0

Location C
LAN-Interface: 172.17.2.25/255.255.0.0
WAN-Interface: 172.18.2.25/255.255.255.0

and so on...


Another idea is to split all connections evenly by using 255.255.255.248 on router and WAN-Interface of the firewall.
Later on it is planned that all offices should be able to contact AD, DNS etc. from the HQ.

I hope you could help me to clarify this problem because otherwise I already see myself driving between all offices for days :)

Thanks in advance!



This thread was automatically locked due to age.