Hello,
I've set up a routed site-to-site IPSec tunnel from my local site (Sophos XG) to an access server (OPNSense). In general I'm trying to get OSPF routing via GRE via IPSec working but for the moment I'm still stuck with the basic IPSec tunnel + fw rules.
This tunnel seems to be working in general.
As you may can see on the screenshot above:
- Access server (OPNSense): 172.16.0.1/32
- Local site (Sophos XG): 172.16.0.2/32
Now I'm trying to reach my local site from the access server:
After that I've double checked my fire wall rules:
Then I tried to find something in the log viewer:
At least the ICMP packets are arriving and are allowed to pass.
Afterwards I've checked the corresponding traffic rule and found that the the WAN rule is being applied to that traffic.
Finally I've checked the policies using the policy tester and found out this interesting stuff:
So I don't get it why the normal ping ACS -> Local Site is matched by rule 13. Why isn't this traffic part of the VPN zone how it's supposed to be.
Thanks in advance for your help!
Edit:
The fact that the traffic isn't matching the auto generated rule 39 is also quite confusing.
Best regards,
Elys
This thread was automatically locked due to age.