Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing with MPLS

Hi,

 I have two Networks. 192.168.100.0/24 and 192.168.101.0/24

The Networks are connected through a MPLS route.

The internal IP for the XG is 192.168.100.1

The MPLS-IP is 192.168.100.254

I did set up a Firewall policy.

Source Zone: LAN

Source Network: Any

Source Services: Any

Destination Zone: LAN

Destination Networks: 192.168.101.0/24

And rewrite Source Adress with the global policy MASQ.

So far I can Access everthing in 192.168.101.0/24 from 192.168.100.0/24

I did set up another policy where source and Destination is switched to the first policy.

But I can't get from 192.168.101.0/24 to 192.168.100.0/24. The trace route Shows that the package get to the Firewall and is then stopped.

What has to be done to get both Networks communicate with each other.

Do I have to add a reroute or something like that ?

Best Regards

Benjamin



This thread was automatically locked due to age.
Parents
  • Benjamin,

    make sure your MPLS network knows the 192.168.100.0/24 with a static route. You should add static route on XG to inform it that network 192.168.101.0/24 exists.
    Make sure to create a network rule from LAN to LAN where source is 192.168.101.0/24 to 192.168.100.0/24.

    Luk
  • Hi Luk,

    thank you for your answer.
    I can't configure the MPLS as this was done by the network group of the building.

    I did set up the route on the firewall and I can ping from Network A to Network B. Idid also create the network rule as in your answer.

    The traceroute from Network B to Network A shows the following hops.

    1. 192.168.101.1 (the gateway in Network B)
    2. some transport net for the MPLS
    3. 192.168.100.254 (the IP of the MPLS router in network A)

    Then it stops.
    But I can ping the firewall in network A. And I can access the Internet from Network B through the firewall in Network A.

    So it has to be a problem with the network rule but I can't figure it out what it is missing. If the route on the MPLS to network A would be missing then I shouldn't be able to ping the firewall or am I wrong ?

    Regards
    Benjamin
Reply
  • Hi Luk,

    thank you for your answer.
    I can't configure the MPLS as this was done by the network group of the building.

    I did set up the route on the firewall and I can ping from Network A to Network B. Idid also create the network rule as in your answer.

    The traceroute from Network B to Network A shows the following hops.

    1. 192.168.101.1 (the gateway in Network B)
    2. some transport net for the MPLS
    3. 192.168.100.254 (the IP of the MPLS router in network A)

    Then it stops.
    But I can ping the firewall in network A. And I can access the Internet from Network B through the firewall in Network A.

    So it has to be a problem with the network rule but I can't figure it out what it is missing. If the route on the MPLS to network A would be missing then I shouldn't be able to ping the firewall or am I wrong ?

    Regards
    Benjamin
Children
No Data