Hi,
I have a VPN connection built from a Sophos XG at the branch and a Palo Alto on the data center end. The VPN is established however, there seems to be some weird routing issues. Both ends have access rules to allow the traffic both ways. Despite the VPN tunnel being up I can't ping across it.
The symptoms I'm seeing are very weird. The VPN tunnels aren't installing routes into the routing table. I had to manually add the remote data center subnet into the vpn tunnel using the system ipsec_route add net command. I now get a ping response every 50 pings or so but when looking at the traffic logs and doing traceroutes, the firewall send the other 49 pings out via the internet connection. For some reason it doesn't realise they need to go over the VPN. The route precedence is also said to prioritise VPN routes.
Has anybody else had this issue?
THanks
Szymon
This thread was automatically locked due to age.