This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Azure Site-to-Site to Point-to-Site routing issue

Hi everyone! 

I'm setting up a lab for a customer PoC and I'm having trouble routing from On-Prem connected by IPSEC Site 2 Site Azure VPN to users dialled in via Azure IKEv2 Point 2 Site and vice versa.. Please see below:

 

The on-prem server can ping and connect to the azure vm and the dialed in user can also ping the Azure server but there is no routing between.. I've tried setting up BGP as often suggested in article and it seems that BGP is being blocked:

 

Both VPNs terminate in the same gateway subnet which MS support fully..

XG Info:

Version: SFOS 17.0.8 MR-8

AP Firmware
11.0.001
-
12:14:24, Dec 28 2017
 
ATP
1.0.0196
-
12:09:45, Jun 05 2018
 
Avira AV
1.0.23261
-
12:10:53, Jun 07 2018
 
Authentication Clients
1.0.0011
-
14:53:09, Mar 17 2018
 
IPS and Application signatures
3.14.87
-
14:11:14, Jun 07 2018
 
RED Firmware
2.0.014
-
05:54:14, Mar 10 2018
 
Sophos AV
1.0.12676
-
06:10:46, Jun 07 2018
 
SSLVPN Clients
1.0.007
-
10:17:47, Aug 11 2017
 
WAF
1.0.0006
-
10:12:04, Aug 11 2017
 

 

Any ideas?

 

Thanks!

 

Darren



This thread was automatically locked due to age.
Parents Reply Children
  • So on the S2S VPN XG has its local subnet in local networks in the VPN settings, then you add the remote networks which will be the Azure VNAT subnet + the P2S VPN Subnet.  Then on Azure VPN settings you add the extra subnet in as its local networks.  Then on the P2S side you add on Azure VPN settings the Local VNET subnet + the XG local subnet, in as its local networks in the vpn settings there and then the P2S endpoint subnet as the remote network.

    As i said Azure VPNs are very fiddly, so some sort of VPN appliance would be a lot easier if you are able to provision one that is.

    JK

  • Dont know how much a basic XG Azure appliance will set you back for but it will prob be a lot simpler to get setup, maintain and be reliable.  Dont get me wrong once you get the Azure VPN settings right for the S2S & P2S youll be fine but im biased as im an XG partner! lol

    If you havent solved it by time i get done with what im doing ill refresh myself of the correct Azure terminology and send over some diags.

  • Just looking again at azure vpn, forgot to ask what VPN type are you using Policy routing or route based?? Forgot about those types, i know now with v17.1 and ikev2 its not such a problem but still will cause grief, thats how often i set these up. first few times were enough to give me nightmares.  Im refreshing myself with Azure VPN as its always changing and doing the diag.

  • Hi John.. Apologies for my lack of response... I've re-set this up again and the result is the same.. I've tried adding the remote VPN network into the IPSEC remote networks and the XG doesn't like it at all.. 

     

     

    Any ideas where else this needs to be set for the XG to acknowledge this subnet?