This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN to IPsec VPN traffic SNAT

Hi all,

We have a 3rd-party IPsec site-to-site VPN service to access some M2M equipment. 

We can access all of the resources on the remote site without issue on when accesing via the LAN zone, but when users connect with SSL remote access VPN, they're unable to access any of the resources at the remote site VPN.

The IPsec config includes the local LAN network (10.10.10.0/24) and the remote network (10.253.27.0/24); I suspect the VPN config means that the remote site will not accept traffic from my SSL remote access VPN clients (using 10.81.234.5-55). 

The remote access SSL VPN includes the remote site's network as a permitted network resource, and network appears in the routing table when a user is connected via SSL remote acess VPN.

I have setup a traffic rule as follows in an attempt to use SNAT, where traffic from the SSL VPN clients is masqueraded as coming from the XG's LAN interface address of 10.10.10.1.

Based on this config, I would imagine that this would allow traffic to flow. Am I missing something?

Thanks and regards,

Ben



This thread was automatically locked due to age.
Parents
  • Hi  

    Welcome to the Sophos Community!

    That setup should work. However, as an alternative (so NAT configuration is unneeded) are you able to submit a request to your third-party so that your SSL VPN subnet can be added to the IPsec tunnel configuration? - (Essentially a hub-and-spoke IPsec setup, you will also need to update your XG configuration to reflect the SSL VPN subnet being included in the IPsec tunnel)

    Regards,

Reply
  • Hi  

    Welcome to the Sophos Community!

    That setup should work. However, as an alternative (so NAT configuration is unneeded) are you able to submit a request to your third-party so that your SSL VPN subnet can be added to the IPsec tunnel configuration? - (Essentially a hub-and-spoke IPsec setup, you will also need to update your XG configuration to reflect the SSL VPN subnet being included in the IPsec tunnel)

    Regards,

Children
No Data