Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Traffic won't go through policy based S2S IPSec tunnel

Hi guys,

I'm trying to setup a policy based site-to-site tunnel, but the traffic won't go through the tunnel. Like the tunnel itself is up and running. Per the others party policy, we had to use SNAT and the needed subnet is not private: 100.270.xx.xx. RB tunnel is not allowed either, btw. I have configured NAT in the IPSec tunnel configuration, as explained in here: https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/SiteToSiteVPN/HowToArticles/S2sVPNIPsecConnectionConfigureNAT/index.html#sophos-firewall-1-configure-firewall-rules_1

Since the destination isn't a private subnet either, I have followed this article: https://support.sophos.com/support/s/article/KB-000038775?language=en_US

Route Precedence is set as follows: vpn, sd-wan, static. Firewall rules were created. Yet, in tcpdump I can see that the packet doesn't go through ipsec0, it flows through my WAN port. Any idea, what I'm missing here?



This thread was automatically locked due to age.