Hello everyone,
We are currently using the SSL VPN to connect our employees from the home office. As our Internet line was very slow, we have now upgraded to a faster line in addition to the previous one. The two lines will run in parallel for a while for testing purposes. During this period, I would like to test the SSL VPN with a small group of users via the new fast line. The line is already connected to a port of the UTM and the public IP is accessible from the Internet. Now I need to configure the interface that is connected to the new line as a new VPN gateway so that the new line can be tested independently of the old line. The test users should be able to log in alternately to both the old and the new VPN gateway.
It is important that the two SSL connections run independently of each other via two different interfaces so that we can check which Internet line is being used.
I have not yet found a way to create a second gateway. How can I achieve my above-mentioned goal?
Best regards
Hi IT Grass ,
Thank you for reaching out to the community, you can utilize the dynamic DNS and use that as a override hostname.
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hi Vivek, could you give me some more information? We have two different lines with a fixed external ip each. How can dynamic DNS help me to solve the above problem?
Could I at least configure the VPN to listen on the two interfaces? I created an interface group but the ssl-config won't accept a group. I can only choose one address or any.
Is there any reason not to just use “Any IPv4”?
For the part with users deciding which line to use, just duplicate the vpn client config and change the target to the new public IP address.