Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem routing WAN traffic across IPSEC

I'm trying to route traffic from WAN across an IPSEC tunnel to a server

WAN -> Sophos1 -> IPSEC -> Sophos 2 -> Server

I've configured firewall rule and NAT rule, then added 'system ipsec_route add net 172.16.1.0/255.255.255.0 tunnelname IPSEC

I also added the WAN IP address to both sides of the IPSEC tunnel so that the Sophos knows where that IP sits.

Packet capture all looks perfectly correct on Sophos1

Problem is, when I do a packet capture on Sophos2 there is no traffic whatsoever. It's as if the traffic doesn't disappears in to the never never.

I've google around and read multiple forums and it all seems to be setup correctly.

What am I missing?



This thread was automatically locked due to age.
Parents Reply
  • Likely not. You see, the NAT is hitting the packet capture. You have to read it from bottom to top. And it is natted and transfered to the XFRM. But nobody is replying. This could due multiple reasons: Firewall rule missing on Peer. Routing on Peer etc. 

    You will likely resolve all of those issues with a SNAT as well. 

Children