this both firewall is Sophos xg 85
This thread was automatically locked due to age.
this both firewall is Sophos xg 85
l3 ipsec vpn is used to connect HO. but BO PC now use HO internet, i want to block internet through IPsec VPN BO PC need to access internet on BO own internet.
Probably, the IPSec is full tunnel (0.0.0.0/0) so basically everything will flow to the HQ. You have some options.
a) Make the IPSec include only the segments that you want to consume (ex: DMZ, Remote LAN, etc)
b) Create a PBR policy to route everything to the internet
First option is actually the recommended one. How do you have setup the IPSEC?