Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing and Firewall Policy for MPLS and IPSec

We have a location where we have Sophos XG106 Firewall serving as Gateway. We have one MPLS link on the location. We are facing issue when we shift / redirect traffic on MPLS link to connect to HO. Static routes are working fine. We are able to reach the BO on MPLS but not vice-versa. Please refer the connectivity diagram as below. We are suspecting it is due to Firewall Rules. We are currently connected using IPSec Tunnel and have Firewall rules set to LAN to VPN and VPN to LAN.

Just unable to understand how to create Firewall Rules for MPLS as the MPLS router is in the same LAN subnet.



This thread was automatically locked due to age.
Parents Reply
  • Hello Vishal,

    Thanks for the reply. To terminate the MPLS link on XG is one consideration, we are in contact with ISP.

    Till then can we have it connectd using XFRM Route based VPN?

    as per the below statement i KB https://support.sophos.com/support/s/article/KB-000044309?language=en_US :

    "In Route-based IPsec site-to-site connection, the XFRM interface is bonded with the interface and the traffic is simply routed through. Using the Stateful inspection bypass for the network between two sites will not cause any issue and will not be inspected by the firewall."

    Also, my current setup is as mentioned in the 3rd solution in KB https://support.sophos.com/support/s/article/KB-000038267?language=en_US

    Create a new connection from the switch on the left to the firewall on the left, set the client default gateway to the firewall's IP, and create a route to MPLS as a backup for the VPN tunnel

    I'm trying to achieve the result using this configuration at BO. But I feel the Firewall Policy is not letting the traffic through. I've achieved this with Fortigate earlier and it worked well, I had to create Policy for LAN to LAN traffic.

Children
No Data