Hi there,
I have been working on this for a couple of days and not getting any where.
I have created an IPSEC site-to-site between two Sophos UTMs (an SG330 and SG105), both on version 9.355-1 firmware.
The IPSEC tunnel says it is up, but it does not look like any traffic is able to pass through. I actually have managed to get traffic through on two occasions with a successful ping test from a computer in the remote network to the HQ network, but this happened randomly and on both occasions stopped working within 5 minutes.
I can create an SSL site-to-site VPN and that comes up instantly and traffic appears to flow correctly between sites (ping and rdp tests), so I'm thinking i can rule out routing issues and narrow the problem down to the IPSEC tunnel itself.
A summary of my setup:
HQ Office (SG330)
internal private lans: 10.1.0.0/16 and 10.10.0.0/16
WAN interface: 220.x.y.z
Remote Gateway settings on HQ SG330 utm:
Name: Branch
Gateway type: Initiate Connection
Gateway: 115.x.y.z
Auth Type: Preshared Key
Remote networks: 10.25.0.0/16
Connection settings on HQ SG330 utm:
Name: BranchConnect
Remote Gateway: Branch
Local Interface: External (220.x.y.234)
Policy: AES-128
Local Networks: 10.1.0.0/16 and 10.10.0.0/16
Automatically firewall rules checked
Remote Office (SG105)
Internal private lan: 10.25.0.0/16
WAN interface: 115.x.y.z (this is a PPOE negotiated dsl connection, but the IP address remains the same)
Remote Gateway settings on Remote SG105 utm:
Name: HQ
Gateway type: Respond Only
Auth Type: Preshared Key
Remote networks: 10.1.0.0/16 and 10.10.0.0/16
Connection settings on Remote SG105 utm:
Name: HQConnect
Remote Gateway: HQ
Local Interface: External (115.x.y.116)
Policy: AES-128
Local Networks: 10.25.0.0/16
Automatically firewall rules checked
Also, as above, having the remote office as the responder and the HQ office as the initiator is the only way i can get the tunnel to come up. Not sure why that is the case.
I have also played around with many different setting options (e.g. use Strict Routing, Bind tunnel to local interface, etc), but nothing seems to help. I always end up with where i am now - the tunnel comes up, but no traffic seems to be going through the tunnel (can't ping, can't rdp).
any help will be greatly appreciated.
regards,
Patrick
This thread was automatically locked due to age.