Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing issues with IPsec (Remote Access)

Hi, 

I am sure this is something that is really easy to fix but I seem to be having some issues with the IPsec (Remote Access) setup. I have followed a detailed setup guide and while I can connect OK, once connected I cannot seem to ping anything on the internal network. I believe I have setup the firewall rules correctly, 

Here are more details:

VPN > IPsec (remote access) :

Assign IP from 10.10.10.10 - 10.10.10.30 (IP Host created for this range called Remote_VPN_Subnet 

DNS Server 1 = 192.168.12.200

Permitted Network - PCL_Subet (192.168.12.X)

Firewall Rule: PCL_Remote_VPN_Access 

Source Zone : VPN

Source Network : Remote_VPN_Subnet 

Destination Zone : PCL_Zone 

Destination Network : PCL_Subnet 

Match Known Users : CHECKED 

Users or Group : PCL_VPN_Users 

Is there another step I am missing? 

Any help would be greatly apprecaited, I am sure I am just missing something small. 

Many thanks, Daniel Hargrove



This thread was automatically locked due to age.
Parents Reply
  • Hi and many thanks for coming back to me. 

    I have checked and Ping is allowed on the VPN zone. It looks like it is set as default. 

    Using the Diagnostics > Packet Capture I can see the following when trying to ping 192.168.12.200 

    Line 1 :

    In Interface - ipsec0

    Out Interface - Port 5

    Source IP - 10.10.10.10

    Destination IP - 192.168.12.200 

    Packet Type - ICMP

    Status - Forwarding  

    Line 2 : 

    In Interface - ipsec0

    Source IP - 10.10.10.10

    Destination IP - 192.168.12.200 

    Packet Type - ICMP

    Status - Incoming  

    After that it goes quiet. 

    Is there anything I need to add to the firewall rules to let the ping result go back out to the client device? 

    Many thanks, Dan 

Children