Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED tunnels connected to XG behind another firewall

Good afternoon all,

Recently I deployed a Fortigate firewall at our edge and replaced the Sophos XG 210 we previously used.  However, I have a remote site connected via a RED device and rather than mess around with another box and IPSec VPN tunnels, I decided to just continue using the RED device and move the XG behind the new Fortigate firewall.  I found the following post which suggested it was possible and used it as a guide:

https://community.sophos.com/sophos-xg-firewall/f/discussions/83528/if-red-can-connect-xg-behind-firewall 

The RED tunnel is up and connected.  Devices can communicate across from the LAN side to the RED side and vice versa.  So far so good.  However where I'm sort of stumped is when it comes to accessing WAN resources; it seems to want to pass the traffic over to the alias WAN interface I created and connected to the Fortigate.  The problem I have is that the Fortigate just sees the traffic as originating from the XG but not who specifically it came from and it makes creating any type of granular rules impossible.  Is there a way to pass the traffic over the LAN side to the Fortigate instead of it using the alias WAN port I created?  I thought about trying to create a static default route but I am not sure what the implications of that might be.  Thanks in advance.

Bill



This thread was automatically locked due to age.