Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to NAT subnet class B to class C through IPSec VPN

Hi Guys,

Need help !!

My company has network subnet class B (ex : 172.16.xx.xx)

I need to setup IPSec VPN connection to our client with subnet class C (ex : 192.168.82.xx)

Here's the diagram 

Question is , how to configure NAT on my device (XG450) ? I still confuse about DNAT / SNAT

Thanks !!!



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Moving this thread to Sophos(XG) firewall discussion.

    As per the network diagram, B side only allows 192.168.99.35/32 subnet. To allow communication between Side A and Side B over IPsec, you'll need to NAT Side A network 172.16.xx.xx/xx with 192.168.99.35/32 subnet.

    Refer to the article below to apply NAT over a Site-to-Site IPsec VPN connection.

    https://support.sophos.com/support/s/article/KB-000035848

    SF1_LAN will be your Side A network

    Local_NATed_LAN will be 192.168.99.35/32 subnet

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Moving this thread to Sophos(XG) firewall discussion.

    As per the network diagram, B side only allows 192.168.99.35/32 subnet. To allow communication between Side A and Side B over IPsec, you'll need to NAT Side A network 172.16.xx.xx/xx with 192.168.99.35/32 subnet.

    Refer to the article below to apply NAT over a Site-to-Site IPsec VPN connection.

    https://support.sophos.com/support/s/article/KB-000035848

    SF1_LAN will be your Side A network

    Local_NATed_LAN will be 192.168.99.35/32 subnet

Children