Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC/NAT interface error

Hello everyone,

i'm challenging a strange behavior on my XG in a special setup.

The XG is Hosted configured by me but is located at the site of a service provider. There is an established IPSEC tunnel between the XG Firewall and Amazon AWS cloud. On the XG Site there is one webserver which has to be accessible from the AWS Cloud and (for some reason) the service provider needs out traffic to be in a specific sub-net. Which means i have to NAT the traffic before i can access the webserver.

So the Setup looks something like this:

Basically the setup works. But from time to time i can't establish a connection between Request Server and the 192.168.1.x Server. The only thing to "resolve" the issue for about a day is to "reconfigure" the Network Interface which is in the 192.168.1.X Server sub-net.

I don't have to change any configuration within the interface, just open settings and save 

i can't really find a pattern when the error occurs. The fix always works for a random amount of time

Kind regards

Mirco



This thread was automatically locked due to age.
Parents
  • If this happens, check the tcpdump, if the packets are routed differently. Also check in the logviewer, which NAT/FW Rule are applied and which interface is used.

    If you save a interface, the routes are applied. Therefore XG might set the same local interface route and it could fix this issue. 

Reply
  • If this happens, check the tcpdump, if the packets are routed differently. Also check in the logviewer, which NAT/FW Rule are applied and which interface is used.

    If you save a interface, the routes are applied. Therefore XG might set the same local interface route and it could fix this issue. 

Children
No Data