This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

v18 - Route based and policy based VPN is not working simultanously?

Hello Sophos Community,

 

I have another question regarding route based VPN tunnels (VPN with tunnel interfaces).

When I enable such a vpn connection, I experience an interruption of our internet connection (we use sophos as webproxy and did not yet migrate to DPI engine with transparent proxy), that lasts until I disable the vpn connection again. I didn't have much time to troubleshoot because it was not a scheduled downtime but it seemed to me as if either the default route was not working anymore (can enabling the tunnel interface for some reason inject a 0.0.0.0/0 route?) or if the wan link itself had an issue after I enabled the tunnel.

 

 

Sophos docs contain a line in the description of the feature that makes me wonder if it is in general not possible to use policy based and route based vpn simultanously. This would be really bad for us, because that would mean, that we would need to migrate ALL of our remote offices at the same time to switch vrom policy based vpn to route based vpn. Is this really the case or what is meant by the last line below?

And if that is the case, is it possible, that this will be improved so a step-by-step migration is possible?

 

http://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/RoutebasedVPN.html

 

Anyone have experience with a "mixed" setup or a hint what I might have overlooked?

The tunnel interface has correct IP setup in a dedicated private network with /30 subnetmask and a route for the remote-office network is pointing at the tunnel interface.

The firewall shows, that the vpn connection is established correctly after activation so I do not assume, there is a basic misconfiguration. If noone here has an easy/obvious answer then I will have to do further troubleshooting. Only thing that irritates me is that line in Sophos docs:

"Route-based VPN tunnels don’t work together with policy-based VPN tunnels in most cases, so you shouldn’t mix them."

 

Thank you in advance!

Kind regards,

David



This thread was automatically locked due to age.
Parents
  • Hi  

    The details available in docs is correct, 

    Route-based VPNs can interoperate with other route-based VPN tunnels, however, they cannot interoperate with policy-based VPNs.
  • This Doc part only covers the Tunnel as such. So a Tunnel on XG site can only be route based, if the peer supports route based and uses Routebased. You cannot connect a device, which is policy based, with a XG as Route based.

     

    But nevertheless XG will support multiple tunnels with multiple settings as routebased and policy based. 

     

    Routebased VPN uses your Routing Stack. So which configuration do you have in Static Routing and SD-WAN Policy based routing, as such configuration can be used with route based. 

     

  • Thx, good to hear, that there is no restriction which vpns can be used side by side.

    This does not explain why I have issues with my internet connection after the tunnel is activated but I think I will just have to dig a little deeper here.

     

    Kind regards,

    David

Reply
  • Thx, good to hear, that there is no restriction which vpns can be used side by side.

    This does not explain why I have issues with my internet connection after the tunnel is activated but I think I will just have to dig a little deeper here.

     

    Kind regards,

    David

Children