This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT destination network through an specific VPN

 Hi everyone. I'm having a problem with a specific configuration.

First of all, my local net is 10.0.0.0/8

 

I've connected successfully my Sophos XG 230 to a IPSEC VPN with a third party with the next network configuration (yes, an /32 network).

The VPN is NATted to "RED 10.0.0.X" which is the network 10.0.0.0/8. Therefore all my network can reach the IP 10.192.214.33 easily

This is so because de remote net only have to receive all the traffic through the IP 192.168.226.17.

 

Now, I need to reach to the IP 172.29.4.212 through this VPN but I don't find the way.

 

I've tried several ways but I can't do this:

  • creating a firewall rule (i cant route the traffic because there isn't a gateway to this VPN)
  • can't create a group of networks to try to nat them in the VPN configuration
  • etc.

 

Could you help me?

 

Thank you very much.



This thread was automatically locked due to age.
Parents
  •   

    Based on your details what I understood is that you want to reach 10.192.214.33  from 172.29.4.212 by NAT IP 192.168.226.17 over the same IPSec tunnel.

    If that is the case then it will not work as you can not choose the same NAT IP 192.168.226.17 for 2 different LAN segments over the same IPSec tunnel. 

    Once you will choose the IP 192.168.226.17 for  "RED 10.0.0.X", you will not get the option to select the same IP  for  "192.168.226.17".

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

Reply
  •   

    Based on your details what I understood is that you want to reach 10.192.214.33  from 172.29.4.212 by NAT IP 192.168.226.17 over the same IPSec tunnel.

    If that is the case then it will not work as you can not choose the same NAT IP 192.168.226.17 for 2 different LAN segments over the same IPSec tunnel. 

    Once you will choose the IP 192.168.226.17 for  "RED 10.0.0.X", you will not get the option to select the same IP  for  "192.168.226.17".

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

Children
No Data