Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing with MPLS

Hi,

 I have two Networks. 192.168.100.0/24 and 192.168.101.0/24

The Networks are connected through a MPLS route.

The internal IP for the XG is 192.168.100.1

The MPLS-IP is 192.168.100.254

I did set up a Firewall policy.

Source Zone: LAN

Source Network: Any

Source Services: Any

Destination Zone: LAN

Destination Networks: 192.168.101.0/24

And rewrite Source Adress with the global policy MASQ.

So far I can Access everthing in 192.168.101.0/24 from 192.168.100.0/24

I did set up another policy where source and Destination is switched to the first policy.

But I can't get from 192.168.101.0/24 to 192.168.100.0/24. The trace route Shows that the package get to the Firewall and is then stopped.

What has to be done to get both Networks communicate with each other.

Do I have to add a reroute or something like that ?

Best Regards

Benjamin



This thread was automatically locked due to age.
Parents
  • Hi Luk,

    I can't configure the MPLS network as this was set up by the network management group of the building.
    I did configure a static route from network A to network B on the firewall and also the network rule.

    I can reach everything from network A to network B. Only the other way make problems.

    If I do a traceroute from network B to network A I get the following output.

    1. 192.168.101.1 (the gateway in network B)
    2. some transport route of the MPLS
    3. 192.168.100.254 (the IP of the MPLS in network A)
    4. 192.168.100.1 (the internal IP of the firewall)
    then it stops.

    But I can ping from network B the firewall in network A (192.168.100.1)
    I can also reach the internet from network B through the firewall in network A
    So imho it must be a problem with the network rule but I can't figure it out what it is missing.

    If the static route on the MPLS to 192.168.100.0/24 would be missing then I wouldn't be able to ping the firewall. Correct or do I miss something there ?

    Best Regards
    Benjamin
  • Thanks for your additional info.
    Anyway you only need a network rule that allows traffic from 192.168.101.0/24 to 192.168.100.0/24.

    What does the Security Policy log say?

    Luk
Reply Children
No Data