Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

BO not able to reach Cloud subnet over IPSec connecting to Head Office.

Hi,

I had configured a ipsec remote access from the cloud using sophos connect to my HQ XGS.

there is a remote Branch that is connected to HQ using IPsec connection.

BO-----------------------------------HQ--------------------------------Cloud

192.168.32.0/24             192.168.0.0/24                      192.168.60.0/24

i have some issue with the routing and it is not able to reach from the BO to the Cloud.

What i had done:

HQ

IPSec VPN added the Cloud subnet and HQ subnet into local subnet.

BO 

Added the Cloud subnet into the remote subnet in IPSec VPN configuration

Added the system ipsec_route of the Cloud and also BO into HQ XGS.

Added the firewall rules to allow Cloud VPN and HQ local subnet inbound and outbound in BO

Added Firewall rules allow BO subnet inbound and outbound in HQ XGS.

currently the network is not able to reach the Cloud subnet (192.168.60.0/24) from the BO site.

Appreciate the advice on how to troubleshoot the routing.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • Hello ben,

    do you have a route FROM the cloud network 192.168.60.0/24 to the BO network with 192.168.32.0/24 in place?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Hi Jprusch,

    The ip address is gotten from the XGS. so the routing that i did is in the XGS console.

    HQ XGS

    BO

    The route in BO is to ensure that the subnet 192.168.60.0 is from the tunnel that is coming from the HQ.

    Regards

    Ben 

  • Hello ,
    Can you check if the traffic is going into the IPsec tunnel or not with the following command: 
    console> system diagnostics utilities route lookup <cloud subnet ip> 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek

    Below is the result 

    BO is connected to HO via IPsec S2S.
    Ho is connected to cloud via remote IPsec.

    Why is this so, its because that the cloud does not have a firewall, so i installed sophos connect to establish a connection between the HQ to the cloud server.

    Regards,

    Ben

  • Hello ,

    First of all SFOS 18.0.3 MR-3 is declared EOL
    KBA: https://support.sophos.com/support/s/article/KB-000035279?language=en_US


    So, would request you to update the firmware to at least SF-OS 18.06 MR-6.

    Now, we know the traffic from BO does travel to HO via IPsec0 tunnel. 

    Now check on the HO, whether the traffic from HO received from BO does it travel to remote IPsec tunnel ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek,

    Thanks for the firmware information, will get the approval for the upgrade of the firmware from the management.

    I had also did some testing and found that the traffic is able to reach the firewall via the IPSec

    above is the log that i captured from the log viewer.

    but still the cloud server is not able to be ping from the remote site.

    can also advice if there is any other command that i can use to trace the routing?

    Regards

    Ben 

  • From the client machine on the command prompt you can use the cmd: route print

    and from the command line interface of the FW appliance you can use: console> traceroute <DEST IP> 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • I still think he is lacking the route back from the cloud net to the BO over the HQ-route or the HQ-Route should be the default gateway for 192.168.60.0/254

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • There is a possibility,  with the commands provided he should be able to determine that !!

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi All,

    The problem is that the IPSec remote access is not able to create a route back on the XGS, and I'm still looking for a way to add in the route for 192.168.60.0/24.

    I do have a SSL VPN access that I created and it works fine when the user connect using that.

    As the IPSec remote access is also getting the IP address from XGS, at first I though that the configuration will be the same.

    But to my surprise it seems not.

    If there is a way to configure the route for the Cloud subnet (192.168.60.0/24), do enlighten me.

    BTW, i tried to add in the static route but due to the IPSec remote configuration, there is no gateway. And it also does not work.

    Sorry for the inconvenience.

    Regards

    Ben 

  • Hello @Vivek Jagad,

    yes, hopefully and he should definitely have the 18.5.x firmware on BO-Site, too.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?