Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Routing (tunnel interface) - XG to SG/UTM connection

I'm trying to migrate UTMs to XG. Currently HQ site has UTM.

BO has a new XG (in test currently) and I can get the IPSec to establish and it has the correct SA if I define the same subnets on each side (typical for the old UTM>UTM style IPsec tunnels).

When I define the Subnets on the XG, a grey note appears (see image) that defining routes or a xfrm interface IP is not required (nor can I do either of these anyways).

On the UTM, the route gets added without an issue. However, on the XG, I'm not getting a route for the remote site subnet and traceroute shows the packets going out the WAN interface (not the tunnel interface) and getting timeouts (of course).

I've watched several of the videos and read a few documents but it seems they all differ slightly in recommendations depending on the version the doc was created for. 



This thread was automatically locked due to age.
Parents
  • The issue appears to be a routing issue along with a bad NAT rule that was auto-loaded on configuration. We are still in the process of debugging and we will edit this correct answer (not the incorrect answer provided by LuCar Toni) at a later date. Thank you.

    EDIT: Issue was with ipsec policy during phase 2 on the SFOS. Corrected and is working now.

  • I do not know, what you mean by incorrect answer? 
    Do you have a Route Based IPsec Tunnel running with a UTM? (And not using Remote/Local Subnet on SFOS end).

    Because i cannot see anything wrong in my answers and was waiting for your config screenshots. 

    __________________________________________________________________________________________________________________

Reply
  • I do not know, what you mean by incorrect answer? 
    Do you have a Route Based IPsec Tunnel running with a UTM? (And not using Remote/Local Subnet on SFOS end).

    Because i cannot see anything wrong in my answers and was waiting for your config screenshots. 

    __________________________________________________________________________________________________________________

Children
No Data