This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG 210 to Fortigate 100C - IPSec Tunnel up, I am unable to pass traffic across tunnel

I am working with my first Sophos devices and am running into a problem passing traffic over an established IPSec VPN tunnel.

I have a VPN tunnel established between Site A (Sophos XG210) and Site B (Fortigate 100c). I created a static route for the remote LAN at Site B on the XG Firewall, which is 10.20.0.0/24 on Port 2 and then configured a static route for Site A remote LAN (10.5.0.0/24) on the Fortigate. I have 2 rules in place on either site, at the top of the policy list. Sophos has LAN All->VPN All and VPN All->LAN All, and on the Fortigate Side LAN All->VPN All and VPN All->LAN All.  IPsec connection on XG Firewall has Local Subnet of Site A (10.5.0.0/24), and Remote Subnet of Site B (10.20.0.0/24). I cannot figure out why I cannot pass any traffic over the tunnel in either direction. Any help would be greatful!



This thread was automatically locked due to age.
Parents
  • Hi support,

    pinging a device on remote network works?

    Luk
  • No, at the time that I posted that, I was not able to ping anything in either direction. There has been some progress made in the last few days, with the help of Sophos support. In addition to the IPSec static route, an SNAT rule was also required making outbound packets through the tunnel have a return address of the sending LAN address range. I am now able to ping from the network behind the XG to the network behind the Fortigate, however I am unable to do the reverse. The next step will be to figure out how to add an SNAT rule to the Fortigate to do the same.
Reply
  • No, at the time that I posted that, I was not able to ping anything in either direction. There has been some progress made in the last few days, with the help of Sophos support. In addition to the IPSec static route, an SNAT rule was also required making outbound packets through the tunnel have a return address of the sending LAN address range. I am now able to ping from the network behind the XG to the network behind the Fortigate, however I am unable to do the reverse. The next step will be to figure out how to add an SNAT rule to the Fortigate to do the same.
Children
No Data