Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED Site to Site Routing

I am trying to get a RED Site to Site connection between a UTM (server) and an XG (client) to work. Here is what I have done so far:

 

1. RED Zone

I defined a RED zone with similar characteristics to the LAN zone.

2. RED Interface in XG

Defined RED interface, provided provisioning file from UTM and assigned zone as RED. Works like a charm!

3. Firewall Rule

Added two simple zone rules. RED to LAN and LAN to RED.

4. Static Routing

This is where I am struggling. In the UTM we defined our rule as gateway under static routing, but I can't seem to find the same in XG. I am guessing that I need to setup a Unicast Route with the desired network on the UTM as the destination and the interface pointing to the RED interface defined above. But what is the gateway? On the UTM the gateway IP points to an interface, but how does this work on the XG?

 

Thank you for your feedback!

Cheers,

Jens



This thread was automatically locked due to age.
Parents
  • Hi Jens,

    You're right it will be a unicast route and you'd set the source as the net behind the XG and the destination gateway to the RED interface IP of the UTM. On the UTM you'd create a gateway route for the net behind the UTM with the target as the XGs RED interface IP address :)

    Other than that, what you've said about the rest of your config looks good!

    Hope that helps you,

    Emile

  • I am still having trouble with this.

    Here is what I have:

    UTM network is 10.10.a.0/24 and XG network is 192.168.b.0/24.

    UTM RED adapter is set to 192.168.c.1 and XG RED adapter is set to 192.168.c.2.

    UTM Static Route is using gateway route type, network is set to 192.168.b.0/24 and the gateway is set to 192.168.c.2.

    XG Unicast Route network is set to 10.10.a.0/24, gateway is set to 192.168.c.1 and the interface is set to RED adapter 192.168.c.2.

     

    No ping is possible and the network cannot be accessed in both directions. RED is showing as connected on both devices.

    What am I missing?

  • Jens,

    If you use the Red to red connection, you only need to create the red configuration (as server) on one end, save the configuration and upload the configuration inside the red client.

    With v16 Red to red is possible between XG and UTM.

Reply Children
No Data