Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

S2S IPSEC - Policy based and Routing based

Hi All,

We have Head Office with 6 Branch Offices. Each Branch office is connected to the Head Office via a Policy Based IPSEC S2S VPN. The head office and branch offices all have 4G backup internet. Hence, this requires 4 tunnels per branch office to cover all possible configurations. We have actually managed to reduce this to 2 tunnels per BO by using DynDNS.

I would like to implement Route Based IPSEC tunnels and then implement SD-WAN policies to route over these using an latency based policy - the tunnel with the lowest latency will be chosen.

I remember seeing something in the past that stated that you should not run both Policy based and Route based VPNs on the same system. I am not sure if this meant on the same Sophos Firewall, or you shouldn't try to connect a route based vpn to a policy based vpn.

Can I can setup Route Based VPNs for 1 of the Branch Office sites and leave the other Branch Offices on policy based VPNs? - this means that the Head Office firewall will be running both Route based and Policy Based VPNs.

Thanks for your time.

Regards

Mike



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Raphael,

    Thanks for all of the great information. I have reviewed the documentation you linked to and, in fact, I have a full test rig set up in a virtualized environment. It comprises one Sophos Firewall acting as 4 ISP connections with 2 connections to a Head office Sophos Firewall and 2 connections to a Branch office Sophos Firewall using Route based VPNs. This way I can "switch off" (or apply QOS) to various connections on the ISP Firewall and watch the Head Office and Branch Office firewalls failover between connections and switch between VPNs automatically.

    This all works really well and showed me all of the technical aspects of getting the xfrms interfaces setup, creating gateways, SDWAN policies, etc.

    To deploy the new configuration, we would like to know if we can do one Branch office at a time. This would mean that after we setup the first branch office, the Head Office Sophos Firewall will be running Policy based VPNs to 5 sites and Route based VPN to the newly configured Branch Office.

    To simplify the question, can a Sophos Firewall run a Route based S2S VPN to one site and Policy based S2S VPN to another site?

    Thanks For your help

    Regards

    Mike

  • can a Sophos Firewall run a Route based S2S VPN to one site and Policy based S2S VPN to another site?
    No, either it policy base on both the sides or route base on both the sides for the same tunnel. 
    You may run two different tunnel i.e. one route base and another policy base !   

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.