<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/zero-trust-network-access/f/discussions/147989/which-ip-address-is-used-for-outgoing-gateway-connection-and-how-to-change-the-outgoing-ip</link><description>I have an ZTNA Client which is connected to an ZTNA Firewall Gateway. 
 The Client is connecting to an ZTNA Ressource (192.168.1.10) which is behind an IPSEC S2S VPN of the Firewall meantioned above as the ZTNA Gateway. 
 The ZTNA Gateway has more configured</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/thread/548657?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 16:09:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2c08834f-1fd8-41fd-93eb-67f9f795585d</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;No, but is this a problem? You can deny traffic there via Firewall rules.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/thread/548636?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 10:51:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:16e601fc-b642-4a89-969d-377ffb8b25cb</guid><dc:creator>Christian Wittmann</dc:creator><description>&lt;p&gt;Ok thanks. Is there another way to NAT it only for ZTNA Ressources?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/thread/548635?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 10:46:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8b1205b6-ae9a-45ff-beb6-3553ee2e27c7</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;As this is an internal service of the firewall itself, there is no ZTNA object.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/thread/548634?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 10:45:34 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:76312e6c-b878-4848-bbfe-da4d09a4e964</guid><dc:creator>Christian Wittmann</dc:creator><description>&lt;p&gt;It is an Policy Based VPN connection.&lt;/p&gt;
&lt;p&gt;I will only NAT the ZTNA Traffic and not all of the Traffic from internal. I have no option to only select ZTNA as Source IP, haven&amp;#39;t I?&lt;/p&gt;
&lt;p&gt;There is no Object ZTNA which I can use as Source IP Address in the NAT Rule.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Which IP Address is used for outgoing Gateway connection and how to change the outgoing IP</title><link>https://community.sophos.com/thread/548632?ContentTypeID=1</link><pubDate>Thu, 14 Nov 2024 10:13:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:95902c98-2aae-4280-b437-5c4c51e7e2c6</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Do you have a Route Based IPsec or Policy Based?&amp;nbsp;&lt;br /&gt;We are using the interface used. For RB IPsec, we can use the XFRM Interface.&amp;nbsp;&lt;br /&gt;For Policy Based, you need this rule:&amp;nbsp;&lt;a id="" href="https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/SiteToSiteVPN/HowToArticles/S2sVPNIPsecCreateIPsecRouteNAT/index.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/SiteToSiteVPN/HowToArticles/S2sVPNIPsecCreateIPsecRouteNAT/index.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>