Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Red Connection Issue between sites and XG Firewall

Hi,

I tried to set up a network connection between a Sophos XG firewall and a Sophos Red.

I follow up the below guides to set up the Red connection:

https://support.sophos.com/support/s/article/KB-000036699?language=en_US

https://community.sophos.com/sophos-xg-firewall/f/discussions/84088/step-by-step-on-how-to-set-up-a-sophos-red-in-a-xg-firewall

Both firewall rules to our internal XG Server Site network (RED Any -> Internal Network)(with MASQ and without MASQ has been tried) and interfaces are set with standard/split mode, the connection is built successfully and could be seen in the XG firewall, we could reach the internet successfully in the RED site, however, we could not reach our internal network on the XG site from RED, by using tracert, we could see the traffic routes to the external network but not able to reach our Firewall.

Is it possible that the connection is UP but due to some routing issues or misconfiguration which does not allow us to reach our internal network?

Thank you.



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Request to follow the steps below to check whether traffic reaches to Sophos Firewall over the RED tunnel or not.

    ==> Go to Diagnostics > Packet capture

    ==> Enter BPF string: host <LAN IP> and proto ICMP, and start the capture

    eg: host 192.168.16.8 and proto ICMP

    ==> Stat a ping to <LAN IP> from an end machine located in RED network.

    It would be great if you can share a snapshot of 'RED network settings' from the RED interface and firewall rule configuration.

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Request to follow the steps below to check whether traffic reaches to Sophos Firewall over the RED tunnel or not.

    ==> Go to Diagnostics > Packet capture

    ==> Enter BPF string: host <LAN IP> and proto ICMP, and start the capture

    eg: host 192.168.16.8 and proto ICMP

    ==> Stat a ping to <LAN IP> from an end machine located in RED network.

    It would be great if you can share a snapshot of 'RED network settings' from the RED interface and firewall rule configuration.

Children
No Data