Hello.
Myself (and a client of mine) currently utilize Sophos XG firewall at the 'main' location of an office/company. We have several remote sites, each with a Site-to-Site VPN tunnel between the two locations.
Traffic can freely and without issue flow from the remote sites into the main site, and get responses back. This behavior works.
However, we need to get the inverse working - from our main office to the remote offices. This is currently not functioning.
From other resources and searches I've done, I've found that we need rules for the home base side of the network to reach out to the remote networks to permit that traffic. However, we already have such a rule and the Policy Checker indicates that rule matches. Traffic still, however, doesn't seem to get handed over the IPSec tunnel to the remote side at the moment. If it were, the remote site would likely be responding.
The rule we've got that SHOULD be permitting our IT Management systems to go over is this:
... where MGMT is the "zone" for the IT Team's management systems and "Source Networks" of "IT" is the 10.1.4.0/24 subnet where they exist.
To my knowledge, the XG should be able to handle routing this traffic over the tunnel, however it doesn't seem to want to do that.
Where should I look next to try and debug this? Do I need special routing rules or such entered to make the traffic actually go over the IPSec tunnel to the remote site?
This thread was automatically locked due to age.