This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AP55 at remote office behind IPSec Site2Site VPN

Hi all,
we are trying to set up an accesspoint (AP55) at a remote office managed by the central UTM at our headquarter but it wont work.

On main site we have a SG550 running 9.403, offsite an ASG120 running 9.405. Both are connected using an IPSec Site2Site VPN Connection.
After adding the „magic-wifi-ip“ (1.2.3.4) under remote networks at remote site and under local networks at main site, the AP is found by the SG550 an everything seems to be fine.
Now when a wifi client tries to connect to the ap offsite it wont get an ip from the dhcp.
The ASG550 recognizes the client and generates a dhcp lease. It also shows the signal, connection speed, hostname and counts up the connectiontime like the wifi-clients at main site.
But the remote wifi-client wont get an ip.

I tried several clients and smartphones. Always the same problem.
Also tried to add the wifi-network under remote networks offsite, but no change.

Is this an official supported scenario, ap behind ipsec site2site vpn?



This thread was automatically locked due to age.
Parents
  • Hi Sebastian,

    I tried configuring the described architecture. Here, you would require a DHCP relay over IPSec as AP will broadcast the DHCP request packets. Unfortunately, DHCP relay through IPSec is a feature request and you can cast your vote here.

    Thanks for the patience.

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi Sebastian,

    I tried configuring the described architecture. Here, you would require a DHCP relay over IPSec as AP will broadcast the DHCP request packets. Unfortunately, DHCP relay through IPSec is a feature request and you can cast your vote here.

    Thanks for the patience.

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data