Hello guys. I am wasting a lot of time with VPN tunnels. Please help me with that.
I am going to setup some IPsec side2side VPN Tunnels from my Sophos XG firewall.
One tunnel is up and running correctly this includes the receiving and sending of data packets. It is setup between my XG firewall and IPfire with PSK. The local network range is different compared to my other networks of course.
Now I am setting up a IPsec Tunnel between an UTM and my XG firewall by using certs. The tunnel is up. Lights are green but nothing is going through the tunnel. I can't ping or ssh or http through it. The firewalls themselfs can't ping each other and the logs don't show up any failures.
On the XG site there are 2 LANs and on the UTM site is one, which should be connected by the VPN. Adresses are matching between UTM VPN configuration and XG VPN configuration (I checked that 5 times now). Both sides are claiming the tunnel is up and the connection is established.
It looks like the firewall is not blocking the traffic. I can't see any blocked traffic in the logs. When I change my selfmade rule from 'accept' to 'block' to test this, the ICMP ping packets appear as blocked in the log. I also didn't forget to make a reverse rule to allow packets in the other direction and on the other firewall.
I guess something is wrong with the routing. I tried the steps suggested in this thread: https://community.sophos.com/products/xg-firewall/f/vpn/92867/ipsec-site-to-site-vpn-connects-but-no-traffic-passes, but I cannot add any routing rules because the GUI name of my VPN is not accepted by the command. On the other side there is no route shown by the command and my 1st VPN connection is running.
The routing on the clients is correct. XG is the only gateway and should handle the routing and since the UTM client LAN has 2 gateways I had to add a rule to the machines for using my VPN. This should allow pings from the clients. And if this does not work, there is still the possibility to ping the firewall itself for testing.
Has anybody an idea what I can do to get this to work.
Best Regards
Jens
This thread was automatically locked due to age.