This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Azure Site-to-Site to Point-to-Site routing issue

Hi everyone! 

I'm setting up a lab for a customer PoC and I'm having trouble routing from On-Prem connected by IPSEC Site 2 Site Azure VPN to users dialled in via Azure IKEv2 Point 2 Site and vice versa.. Please see below:

 

The on-prem server can ping and connect to the azure vm and the dialed in user can also ping the Azure server but there is no routing between.. I've tried setting up BGP as often suggested in article and it seems that BGP is being blocked:

 

Both VPNs terminate in the same gateway subnet which MS support fully..

XG Info:

Version: SFOS 17.0.8 MR-8

AP Firmware
11.0.001
-
12:14:24, Dec 28 2017
 
ATP
1.0.0196
-
12:09:45, Jun 05 2018
 
Avira AV
1.0.23261
-
12:10:53, Jun 07 2018
 
Authentication Clients
1.0.0011
-
14:53:09, Mar 17 2018
 
IPS and Application signatures
3.14.87
-
14:11:14, Jun 07 2018
 
RED Firmware
2.0.014
-
05:54:14, Mar 10 2018
 
Sophos AV
1.0.12676
-
06:10:46, Jun 07 2018
 
SSLVPN Clients
1.0.007
-
10:17:47, Aug 11 2017
 
WAF
1.0.0006
-
10:12:04, Aug 11 2017
 

 

Any ideas?

 

Thanks!

 

Darren



This thread was automatically locked due to age.
Parents
  • Prob the case but the Point to site VPN is setup to use the default gateway on the VPN right?

    Can you post your Firewall rules on Azure pls?

    Anyreason why your not using SSL VPN? Sorry are you using XG Azure appliance?? Or out the box Azure VPN's?

    Ta

    JK

  • Hi John

     

    hanks for your reply.. The P2S VPN by default is "force tunneled". Take a look at the config below when dialed in:

     

    Route print shows:

     

     Firewall rules as follows:

     

    SSL VPN is simply not secure enough for the client.

    Darren

  • Dont know about not sucure but its the clients decisions i find. lol!

    So do you use XG Azure Appliance then? Or standard Azure VPN? Either way do you have the used Subnets setup at each point as each point in the link will need to know the subnets you want routed.  So the Site to Site has to have the subnets used in the Site to Point and vice versa?? Have you got those in??

    Sorry just trying to get my head round your setup, I can def advise Azure XG appliance as i know from experience Azure VPNs are a pain.

     

    JK

  • Ours is not to reason why :-)

     

    It's a dedicated box Caswell CAR3000 with 6x 1Gbe built in.

     

    Darren

Reply Children