This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Azure Site-to-Site to Point-to-Site routing issue

Hi everyone! 

I'm setting up a lab for a customer PoC and I'm having trouble routing from On-Prem connected by IPSEC Site 2 Site Azure VPN to users dialled in via Azure IKEv2 Point 2 Site and vice versa.. Please see below:

 

The on-prem server can ping and connect to the azure vm and the dialed in user can also ping the Azure server but there is no routing between.. I've tried setting up BGP as often suggested in article and it seems that BGP is being blocked:

 

Both VPNs terminate in the same gateway subnet which MS support fully..

XG Info:

Version: SFOS 17.0.8 MR-8

AP Firmware
11.0.001
-
12:14:24, Dec 28 2017
 
ATP
1.0.0196
-
12:09:45, Jun 05 2018
 
Avira AV
1.0.23261
-
12:10:53, Jun 07 2018
 
Authentication Clients
1.0.0011
-
14:53:09, Mar 17 2018
 
IPS and Application signatures
3.14.87
-
14:11:14, Jun 07 2018
 
RED Firmware
2.0.014
-
05:54:14, Mar 10 2018
 
Sophos AV
1.0.12676
-
06:10:46, Jun 07 2018
 
SSLVPN Clients
1.0.007
-
10:17:47, Aug 11 2017
 
WAF
1.0.0006
-
10:12:04, Aug 11 2017
 

 

Any ideas?

 

Thanks!

 

Darren



This thread was automatically locked due to age.
Parents Reply Children
  • OK so your remote networks on XG add the point to site subnets too then on Azure S2S you need to then add the additional subnet to its local networks so the vpn there connects.  Then you need to do the same on the other side. point to site add the xg subnets on the azure end if you get what i mean..

    As long as both sides on the Azure part has the subnet of both vpns it should work. sorry if im being vague, if you can wait till i get through my morning emails ill draw it on ur diag.

    To add you will change the XG firewall rules to match.

    JK

  • Splendid.. Really appreciate that.. I have tried adding the VPN pool address range ito the remote subnet of the IPSEC VPN and it refuses to accept it but I my be doing that incorrectly.. Drawing it into the diagram would be great thanks..

     

    TIA

    Darren

  • TBH never set BGP up so cant add to that, but the way i mentioned is the manual method to set that up without needing BGP.

  • When you added the extra Remote subnet on XG did you also add that into the S2S vpn setup on Azure as it has to match or the VPN wont connect.

  • Azure VPNs are very fiddly anyway, you would do yourself a favor if you could setup an Azure XG Appliance.....  Would def simplfy things....

  • Hi John..

     

    Where would I add that in Azure? On the Virtual Network Gateway?


    Darren

  • Did you add the remote networks of the P2S VPN in the XG firewall rules too?? If your using BGP it could just be firewall rules??

    JK

  • So on the S2S VPN XG has its local subnet in local networks in the VPN settings, then you add the remote networks which will be the Azure VNAT subnet + the P2S VPN Subnet.  Then on Azure VPN settings you add the extra subnet in as its local networks.  Then on the P2S side you add on Azure VPN settings the Local VNET subnet + the XG local subnet, in as its local networks in the vpn settings there and then the P2S endpoint subnet as the remote network.

    As i said Azure VPNs are very fiddly, so some sort of VPN appliance would be a lot easier if you are able to provision one that is.

    JK

  • Dont know how much a basic XG Azure appliance will set you back for but it will prob be a lot simpler to get setup, maintain and be reliable.  Dont get me wrong once you get the Azure VPN settings right for the S2S & P2S youll be fine but im biased as im an XG partner! lol

    If you havent solved it by time i get done with what im doing ill refresh myself of the correct Azure terminology and send over some diags.

  • Just looking again at azure vpn, forgot to ask what VPN type are you using Policy routing or route based?? Forgot about those types, i know now with v17.1 and ikev2 its not such a problem but still will cause grief, thats how often i set these up. first few times were enough to give me nightmares.  Im refreshing myself with Azure VPN as its always changing and doing the diag.