Guest User!

You are not Sophos Staff.

Parents
  • Our users access a public 3rd party website that enforces an access list tied to client wan ip.  Our vpn clients are not configured to route external traffic to the XG and instead use their local isp.  We therefore include the /20 network address of this website in the "remote_ts" section of our Sophos Connect ipsec vpn client SCX files so that traffic from those clients to the webpage routes through our XG wan interfaces rather than the vpn client local isp.   The "Permitted network resources" section in the XG VPN config includes this /20 network address.  This worked in SFOS 17.x - 18.x but now breaks on each XG that is updated from 18.5 mr4 to 19 mr1.  XG log shows the firewall rule allows the traffic and nats but the page will no longer load in the vpn client browser.  I experimented with various alternate ways to nat from the web interface with no change.  As a workaround static routing traffic to this website's ip in the VPN client's XG to another XG still on SFOS 18.5 through a RED connection fixes the problem but is not ideal and will no longer work when the target XG is updated to SFOS 19.  This is being looked into in case #05656076.

Reply
  • Our users access a public 3rd party website that enforces an access list tied to client wan ip.  Our vpn clients are not configured to route external traffic to the XG and instead use their local isp.  We therefore include the /20 network address of this website in the "remote_ts" section of our Sophos Connect ipsec vpn client SCX files so that traffic from those clients to the webpage routes through our XG wan interfaces rather than the vpn client local isp.   The "Permitted network resources" section in the XG VPN config includes this /20 network address.  This worked in SFOS 17.x - 18.x but now breaks on each XG that is updated from 18.5 mr4 to 19 mr1.  XG log shows the firewall rule allows the traffic and nats but the page will no longer load in the vpn client browser.  I experimented with various alternate ways to nat from the web interface with no change.  As a workaround static routing traffic to this website's ip in the VPN client's XG to another XG still on SFOS 18.5 through a RED connection fixes the problem but is not ideal and will no longer work when the target XG is updated to SFOS 19.  This is being looked into in case #05656076.

Children
No Data