Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNAT Internal Traffic Across IPSec Tunnel Interface

I have a server at site B that has been relocated to site A. Workstations at site A are still pointing to what used to be the server's internal IP at site A, 2.2.2.2. I have built an IPSec tunnel interface between the two sites with respective static routes and confirmed the two subnets can talk across the tunnel. The server, now at site B with internal IP 3.3.3.3, needs to be accessible across the IPSec tunnel by workstations at site A via the server's old IP 2.2.2.2. I have created a static route on site A's firewall to force all traffic destined for the server's old IP to use the IPSec tunnel interface. I have also created a NAT rule on site A's firewall that translate all traffic destined for the server's old IP, 2.2.2.2, to the server's new IP at site B, 3.3.3.3. This setup is not working and I am needing help before I tell the customer it just won't work this way lol.

In a nutshell, I need to forward traffic from LAN resources at site A destined for the internal IP 2.2.2.2 across the IPSec tunnel to site B to the internal IP 3.3.3.3. The point in all this is to avoid updating the server's new IP address on the unpractical number of workstations pointing at the server's old address.

Thanks in advance for your input!



This thread was automatically locked due to age.