Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

BO not able to reach Cloud subnet over IPSec connecting to Head Office.

Hi,

I had configured a ipsec remote access from the cloud using sophos connect to my HQ XGS.

there is a remote Branch that is connected to HQ using IPsec connection.

BO-----------------------------------HQ--------------------------------Cloud

192.168.32.0/24             192.168.0.0/24                      192.168.60.0/24

i have some issue with the routing and it is not able to reach from the BO to the Cloud.

What i had done:

HQ

IPSec VPN added the Cloud subnet and HQ subnet into local subnet.

BO 

Added the Cloud subnet into the remote subnet in IPSec VPN configuration

Added the system ipsec_route of the Cloud and also BO into HQ XGS.

Added the firewall rules to allow Cloud VPN and HQ local subnet inbound and outbound in BO

Added Firewall rules allow BO subnet inbound and outbound in HQ XGS.

currently the network is not able to reach the Cloud subnet (192.168.60.0/24) from the BO site.

Appreciate the advice on how to troubleshoot the routing.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • Hi Vivek,

    Thanks for the firmware information, will get the approval for the upgrade of the firmware from the management.

    I had also did some testing and found that the traffic is able to reach the firewall via the IPSec

    above is the log that i captured from the log viewer.

    but still the cloud server is not able to be ping from the remote site.

    can also advice if there is any other command that i can use to trace the routing?

    Regards

    Ben 

Children
  • From the client machine on the command prompt you can use the cmd: route print

    and from the command line interface of the FW appliance you can use: console> traceroute <DEST IP> 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • I still think he is lacking the route back from the cloud net to the BO over the HQ-route or the HQ-Route should be the default gateway for 192.168.60.0/254

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • There is a possibility,  with the commands provided he should be able to determine that !!

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi All,

    The problem is that the IPSec remote access is not able to create a route back on the XGS, and I'm still looking for a way to add in the route for 192.168.60.0/24.

    I do have a SSL VPN access that I created and it works fine when the user connect using that.

    As the IPSec remote access is also getting the IP address from XGS, at first I though that the configuration will be the same.

    But to my surprise it seems not.

    If there is a way to configure the route for the Cloud subnet (192.168.60.0/24), do enlighten me.

    BTW, i tried to add in the static route but due to the IPSec remote configuration, there is no gateway. And it also does not work.

    Sorry for the inconvenience.

    Regards

    Ben 

  • Hello @Vivek Jagad,

    yes, hopefully and he should definitely have the 18.5.x firmware on BO-Site, too.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Hey ,

    Can you confirm if under the IPsec remote access if the default gateway is enabled ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek,

    I didn't enable the default gateway,

    If I enable this will I loss the WAN IP connection from the cloud? 

    Regards

    Ben 

  • Well , enabling that option will send all traffic, including external internet requests, to the interface you specify for IPsec remote access. With that client users will send their internet requests through Sophos Firewall, and you will need to configure a firewall rule with the source zone set to VPN and the destination zone set to WAN. 

    For HO it is already accessible right? So clients will considered on the local firewall, that should work if you have allowed the cloud subnet to communicate. 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Yes, that's the dilemma! You probably do not want this as the default gateway there.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek,

    Thanks for the recommendation, will check with my manager if he is okay with the solution tomorrow.

    Regards

    Ben

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?