Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN Remote Access Split Tunnel ?

We have an XG125w firewall with SSL VPN Remote Access setup for a few users to connect in from home.  It is currently setup to use split tunneling so Internet access is quick.

 

We have 1 hosted application the end users access by going to example123.something.com that is only allowed from our Public WAN IP Address at the office.

 

Is there a way to force traffic going to example123.something.com route over the VPN and out the XG's WAN interface so it is accessible to the SSL VPN Users?



This thread was automatically locked due to age.
  • Hi  

    Is your server hosted behind the firewall and DNAT configuration is there to access it using public IP from WAN?

    Please follow the below given steps to achieve your requirements.

    1. Find out A record of your domain example123.something.com

    2. Add this A record IP address to the Accessible Resource of SSL VPN configuration

    3. Reimport the SSL VPN client configuration, it will push the A record route to the user system

    4. When the user tries to access the URL, it will forward through the VPN tunnel to XG.

    5. XG will try to find the route in its local table and unable to find the route and forward the traffic to the WAN zone.

    6. Create a VPN to WAN zone rule and web site will be accessible to SSL VPN users in your scenario.

    7. If traffic should be sent through a specific gateway, please define that gateway as "Primary Gateway" in VPN to WAN rule.

    Regards,

    Keyur
    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Keyur,

     

    Thanks so much. That was the fix!

     

    I appreciate your time and explanation, that helps me understand what I did as well as correct the issue.