Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

nat rule replace destination and masquerade

hello community,

i try to reach a device in a subnet A from another subnet B.

problem1: the device in subnet A has no route to firewall (only local subnet with firewall). so i have to use masquerade to get reply packets.

problem2: i have to use a nated ip for device, because it's original ip cannot be used for routing from source subnet B, because of overlapping ip ranges.

i tried it with one nat rule replacing destination and MASQ. outbound interface is local interface selected which is connected to target device in subnet A.

in paket capture i can see incoming pakets from vpn with device nated ip as target. but paket is not forwarded by firewall.

any ideas? is it possible to implement this scenario with sophos firewall?

thank you.

kind regards,

Chris



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thanks for reaching out to Sophos Community and hope you are well. 

    Kindly provide at network diagram and traffic flow you are trying to achieve on this use case. 

    Also, you may freely reach out to your local Sales Engineer, local Partner if this is an implementation/deployment activity and I believe they are also able to help you

    with your setup.

    Thanks for your time and patience and thank you for choosing Sophos

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Reply
  • Hello there,

    Thanks for reaching out to Sophos Community and hope you are well. 

    Kindly provide at network diagram and traffic flow you are trying to achieve on this use case. 

    Also, you may freely reach out to your local Sales Engineer, local Partner if this is an implementation/deployment activity and I believe they are also able to help you

    with your setup.

    Thanks for your time and patience and thank you for choosing Sophos

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Children
No Data