Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Configure Sophos XG With VPN Draytek (Vigor 2915)

Hello , Please I need help with this case

I have 2 Sites A and B

 In Site A:    I have Sophos XG With  2 Wan Link from different ISP Direct Connected to Sophos  and one LAN port 192.186.1.101 connected to Lan Switch , All PCs in LAN have GW : 192.186.1.101

In Site B : I Don't have Sophos just ADSL Router

I want to use VPN Draytek Vigor 2915 to link Two sites with vpn draytek matcher but i face problem

1- i need best topology between draytek and sophos on  Site A

2- i want select traffic from lan in site A to Site B ( Over VPN Vigor ) exit from second ADSL Link with know all PCs have gw 192.186.1.101 not Vigor GW

In Site A if PC has vigor ip as GW the connection vpn work well , if has sophos lan ip the connection loss but from site B ( i can't ping from B To A But i can ping from A To B )



This thread was automatically locked due to age.
Parents
  • Two things:
    1. This design is broken.Why use a 192.186.1.0 as your network? This is publicly assigned. You ask for "best" topology: use 192.168.2.0/24 for Site A and 192.168.1.0/24 for Site B.

    2. This is a kind of "wash me, but don't make me wet" question/wish: the vigors are your endpoints for the VPN tunnel. So these are the gateways, basta. What you try to do is assymetric, you should avoid this. So to correct this, the vigor in site B has to know a route to the LAN in site A.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Two things:
    1. This design is broken.Why use a 192.186.1.0 as your network? This is publicly assigned. You ask for "best" topology: use 192.168.2.0/24 for Site A and 192.168.1.0/24 for Site B.

    2. This is a kind of "wash me, but don't make me wet" question/wish: the vigors are your endpoints for the VPN tunnel. So these are the gateways, basta. What you try to do is assymetric, you should avoid this. So to correct this, the vigor in site B has to know a route to the LAN in site A.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children