This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN - setup. users can vpn in, but can't reach Local LAN.

Good morning all, 

I have an XG 125 (fw 17.0.5 MR-5) with the total protect bundle.

I'm trying to setup the SSL VPN for user remote access, and following these guides exactly.

 

https://community.sophos.com/kb/en-us/122769

Also checked this one, which is pretty much the same.

https://shred086.wordpress.com/2017/12/06/setting-up-ssl-vpn-access-to-lan/

Also tried the trouble shooting guide.

https://community.sophos.com/kb/en-us/127189

 

Basically, I can create the VPN connection, just can't see anything on our internal LAN.

Pings, tracerts, intranet pages, nmap.. nothing from the LAN responds.

 

I'm guessing there is a problem with the FW rule as I'm getting connected OK, just the traffic isn't routing over to the LAN.

 

Firewall rule

Rule

Apply "None" app filter, "None" web filter, for "DL_VPN_Group" group, when in "VPN" zone, and coming from "remote SSL VPN Range" network

Source & Schedule
VPN

Source Networks and Devices : remote SSL VPN Range
During Scheduled Time : All the Time

Destination & Services
LAN

Destination Networks : Any
Services : Any

 

On the VPN client laptop, a route print shows that the routes created by the VPN are correct.

 

Is there a step I'm missing?

 

Any pointers would be really appreciated, I'm new to Sophos Fw's and still finding my feet.

 

 

Many thanks

Dave



This thread was automatically locked due to age.
Parents
  • Hi,

     

    I haved the same issu with a XG125 last firmware 17 and remote access vpn client and site to site vpn with cyberoam firewall last firmware 10.6

     

    I fixed it with downgrade the encryption policy at 128bits. Some times you must  recreate the VPN Ipsec Connection and downgrade the encryption policy at 128bits.

     

    Erick.

Reply
  • Hi,

     

    I haved the same issu with a XG125 last firmware 17 and remote access vpn client and site to site vpn with cyberoam firewall last firmware 10.6

     

    I fixed it with downgrade the encryption policy at 128bits. Some times you must  recreate the VPN Ipsec Connection and downgrade the encryption policy at 128bits.

     

    Erick.

Children
No Data