I think this has been answered somewhat indirectly in the forum more than once, but I want to ensure that my understanding is correct by asking in the most direct way possible.
Is there any way to route select traffic (might be by source, might be by application, might be a combo) that is bound for the internet to a device on a network at the far end of an ipsec tunnel?
- My side of the ipsec tunnel: Sophos XG
- Remote tunnel termination: non-Sophos
- Remote "security device" that I want to direct select internet-bound traffic through: non-Sophos, and not the same device as the tunnel termination
My inclination would be to use policy routing for this. But policy routing needs a Gateway object as a destination. I don't think that my remote security device can be defined as one, since it is not on the same network as any of my XG's interfaces (?).
My ipsec tunnel works. My source hosts can reach the remote security device over the tunnel. I just need to know if the XG is able to direct select internet-bound from select source hosts of to that remote security device.
Thanks.
bc
This thread was automatically locked due to age.