This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect Client allow access to remote sites

Hi,

i want to configure the Sophos Connect Client to access the main network and two remote Sites.

Here is an quick overview of my current network configuration:

Main Office (XG125): 10.1.1.0/24

Branch Office 1: 10.1.2.0/24

Branch Office 2: 10.1.4.0/24

 

If I now connect to the main office with the client, then I cannot access the two branches. In the sophos connect client settings i set an IP- Range inside the main office range but then i can only access the two branches and no longer access the main office network.

If I use another range, such as 10.1.10.100 to 10.1.10.200, then I can only access the main office.

Can you tell me what I'm doing wrong?

 

Best regards

fireb



This thread was automatically locked due to age.
Parents
  • Hello

    I assume that your branch offices are connected by IPSec tunnels?

     

    You will need a firewall rule for VPN to VPN traffic to forward the Sophos Client IP range to the other IPSec tunnels

    You will need routing entries at the other firewalls to route back to the Main office Sophos for the Connect Client Range

     

    Regards

  • Hello,

    sorry, I forgot to say. The branch offices are connected over site 2 site SSL-VPN. Does that also work?

    This is the Firewall Rule on the Main Firewall. I created the same rule on the firewall in the branch office.

    Access works perfectly from both sides. Except via the Sophos Connect Client, where I can only access the network in the main office.

     

    Regards

Reply
  • Hello,

    sorry, I forgot to say. The branch offices are connected over site 2 site SSL-VPN. Does that also work?

    This is the Firewall Rule on the Main Firewall. I created the same rule on the firewall in the branch office.

    Access works perfectly from both sides. Except via the Sophos Connect Client, where I can only access the network in the main office.

     

    Regards

Children
No Data