This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cant connect to the Plesk samba file share through ssl vpn (remote access)

Hi

 

I have a  LAN that is set as follows :

 

INTERNET --- ISP ROUTER (192.168.1.250) ----- DMZ: SOPHOS XG Firewall (192.168.1.251 / 192.168.16.250) --- LAN (192.168.16.x)-- Debian Plesk server 192.168.16.239

 

The ssl vpn (remote access) perfectly works with the help of https://community.sophos.com/products/xg-firewall/f/network-and-routing/119587/ssl-vpn-remote-access-behind-the-isp-router/

On the remote Windows PC my remote IP  granted by the VPN is 10.81.234.6

I can ping 192.168.16.239 (the SMB file share) BUT I can't connect to the debian Plesk samba folder on \\192.168.16.239

 

Is there something special to do either on the XG or the SMB share ?

 

thanks

 

Cyril

 

 



This thread was automatically locked due to age.
Parents
  •  

    here is the samba config page on the plesk. I thought we would need to specify the remote VPN granted IP range but got no luck either here

     

    thanks

  • Hi  

    Could you please create SMB service port 445 firewall rule for VPN to DMZ zone and place the rule on top and do not apply NAT (MASQ) and verify the access and also add Netbios Ports-139 udp/tcp in the same rule and share the status.

  • Hi

    Thanks for your answer. I don't fully understand what you propose :

    1- I create a SMB service with the 445 port (see screenshot)
    2- "firewall rule for VPN to DMZ zone " : can't understand here : the DMZ is just the LAN port of the ISP router: all the trafic passes through the router without any filtering. Can you explain what you expect here please ?
    3- should I create a user/network rule or a Business application rule?


    Thanks for your help

    Cyril

  • Hi  

    In the Sophos XG, please create a user/network rule from VPN zone to LAN zone (where your system is hosted) be it a LAN or DMZ. and add services SMB and NetBIOS as suggested earlier and in the option of NAT do not apply anything and create a rule.

  • Thanks 

     

    Sorry but there are still thing I'm missing here :

     

    1- I created the SMB service :

     

    the SAMBA service (port 139) already exists

     

    2- I created the firewall rule :

     

    3- here is the rules order :

     

     

    but on the remote PC I still can't access the samba share

     

    Did I miss something please?

     

    Thanks

     

    Cyril

Reply
  • Thanks 

     

    Sorry but there are still thing I'm missing here :

     

    1- I created the SMB service :

     

    the SAMBA service (port 139) already exists

     

    2- I created the firewall rule :

     

    3- here is the rules order :

     

     

    but on the remote PC I still can't access the samba share

     

    Did I miss something please?

     

    Thanks

     

    Cyril

Children