Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem routing WAN traffic across IPSEC

I'm trying to route traffic from WAN across an IPSEC tunnel to a server

WAN -> Sophos1 -> IPSEC -> Sophos 2 -> Server

I've configured firewall rule and NAT rule, then added 'system ipsec_route add net 172.16.1.0/255.255.255.0 tunnelname IPSEC

I also added the WAN IP address to both sides of the IPSEC tunnel so that the Sophos knows where that IP sits.

Packet capture all looks perfectly correct on Sophos1

Problem is, when I do a packet capture on Sophos2 there is no traffic whatsoever. It's as if the traffic doesn't disappears in to the never never.

I've google around and read multiple forums and it all seems to be setup correctly.

What am I missing?



This thread was automatically locked due to age.
Parents Reply
  • Yes I agree. SNAT was actually my first thought and is most logical, but if I put an SNAT in, it doesn't even route across the tunnel at all and just does straight out to the internet with no NAT or FW rules appled, which seems odd. I even tried a system SNAT. Screenshot below. If I remove the SNAT, packet capture shows it going across the tunnel, but never gets to the other end.

    I also tried putting the WAN IP address on both ends of the tunnel so that the Sophos knew to return traffic to the IPSec tunnel

    Before SNAT:

    After SNAT:

Children
No Data