Hi there. I have the following Setup:
Location AMS with a ASG220 and the 172.30.129.0/24 network. Location BSL has a ASG120 with the 172.30.130.0/24 network.
I have a working IPSec Site-Site VPN between AMS and BSL.
AMS (172.30.129.0/24 BSL (172.30.129.0/24)
Now I need to connect to an external party. Let's call them MM. They have a Cisco VPN concentrator. I need to make 8 hosts visible. I created a IPSec Site-Site between AMS and MM where in the Remote Gateway definition of MM I added the 8 hosts in the Remote Network. This works fine from AMS.
MM (192.168.10.12/32, 192.168.12.87/32 ...) AMS (172.30.129.0/24) BSL (172.30.130.0/24)
Now my clients at BSL also need to access those 8 hosts. I read in another post (https://community.sophos.com/products/unified-threat-management/astaroorg/f/58/t/53407) with a similar problem.
So in the AMS to BSL VPN I added in the remote gateway in BSL (which points to AMS) the 8 hosts as remote network. On the AMS side of this VPN I added the 8 Hosts as local network.
In the AMS to MM VPN I added the BSL network (172.30.130.0/24) as local network.
VPNs come up all green. When I do a traceroute from BSL to a host in AMS I see it going through the tunnel, but a trace to one of the 8 hosts it exits at BSL through the Internet Interface (EXT) and does not go through the AMS-BSL VPN.
I'm I missing something? Am I totally unclear? How can I proceed to debug this problem? Does anyone has an idea?
This thread was automatically locked due to age.