Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC endpoint on a non WAN zone interface

HI All,

I suspect that this will either be easy or not possible. 

We have an XG with multiple WAN interfaces, for one of these the ISP dynamically allocates the gateway via BGP, as it doesn't have a static gateway this interface can't be added to a WAN zone (so has been setup as a LAN zone). 

Is there a way I can enable this interface to as a VPN endpoint? looking at the options when enabling IPsec it appears that it can only be enabled in the WAN zone - so won't allow me to enable in this interface. 

Am I missing something simple here or is it not possible?

(I do have a work around I may end up applying, which is to forward IPSec traffic received on the relevant IP else where, don't really want to do this though as it adds complexity)



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out to the Community! 

    You can only use the WAN interface as a listening interface while configuring IPsec site-to-site VPN. The interfaces that aren’t in the WAN zone won't appear in the drop-down.

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out to the Community! 

    You can only use the WAN interface as a listening interface while configuring IPsec site-to-site VPN. The interfaces that aren’t in the WAN zone won't appear in the drop-down.

    Thanks,

Children
No Data