This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AP55 at remote office behind IPSec Site2Site VPN

Hi all,
we are trying to set up an accesspoint (AP55) at a remote office managed by the central UTM at our headquarter but it wont work.

On main site we have a SG550 running 9.403, offsite an ASG120 running 9.405. Both are connected using an IPSec Site2Site VPN Connection.
After adding the „magic-wifi-ip“ (1.2.3.4) under remote networks at remote site and under local networks at main site, the AP is found by the SG550 an everything seems to be fine.
Now when a wifi client tries to connect to the ap offsite it wont get an ip from the dhcp.
The ASG550 recognizes the client and generates a dhcp lease. It also shows the signal, connection speed, hostname and counts up the connectiontime like the wifi-clients at main site.
But the remote wifi-client wont get an ip.

I tried several clients and smartphones. Always the same problem.
Also tried to add the wifi-network under remote networks offsite, but no change.

Is this an official supported scenario, ap behind ipsec site2site vpn?



This thread was automatically locked due to age.
Parents Reply Children
  • Also, Sebastian, you say that a lease is established but that the laptop never receives the IP.  Please show us the part of the Wireless Protection log where the lease is generated.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Good catch, Sachin!

    Sebastian, Although it's slightly slower than an AES 128 IPsec tunnel, this is a perfect situation for a RED tunnel as DHCP will transit a RED tunnel with the proper configuration.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA