I have 3 sites (A, B, and C).
Site A: 172.16.16.0/24
Site B: 192.168.1.0/24
Site C: 10.23.1.0/24
Site A and B are both Sophos XG firewalls configured with a route based IPSec tunnel interface between each other
Site C is remote and is outside our management scope. Site B and C are connected with a traditional policy-based IPSec tunnel.
I would like to connect from site A to site C where site B needs to NAT the traffic coming from A going to C.
I have already created a static route in Sophos Site A for 10.23.1.0/24 to be routed to the tunnel interface just the same as the existing route to site B that was already configured.
I tried to configure a NAT rule in site B for traffic coming from 172.16.16.0/24 going to 10.23.1.0/24 to translate the source to an IP-address in the 192.168.1.0 range, but this NAT rule doesn't seem to work as no traffic is using this rule.
How can I achieve this?
This thread was automatically locked due to age.