Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED Site to Site Routing

I am trying to get a RED Site to Site connection between a UTM (server) and an XG (client) to work. Here is what I have done so far:

 

1. RED Zone

I defined a RED zone with similar characteristics to the LAN zone.

2. RED Interface in XG

Defined RED interface, provided provisioning file from UTM and assigned zone as RED. Works like a charm!

3. Firewall Rule

Added two simple zone rules. RED to LAN and LAN to RED.

4. Static Routing

This is where I am struggling. In the UTM we defined our rule as gateway under static routing, but I can't seem to find the same in XG. I am guessing that I need to setup a Unicast Route with the desired network on the UTM as the destination and the interface pointing to the RED interface defined above. But what is the gateway? On the UTM the gateway IP points to an interface, but how does this work on the XG?

 

Thank you for your feedback!

Cheers,

Jens



This thread was automatically locked due to age.
  • Hi Luk,

    Here is what I got.

     

    Based on your feedback I have made some changes to both rules and this has improved things. In specific, I unmarked matched users. I was assuming that Any means that it would work with any user, but I guess any means any authorized user. Thank you again for your help on finding that problem!

    Unfortunately, there are still more issues. While I can ping everything just fine, I can't connect to anything. IMAP, SMTP and web server all don't work. It seems that my zone role above doesn't allow all traffic or I am still missing another setting somewhere...

    Any suggestions?

    Thanks,

    Jens

  • It turns out that the XG doesn't support tunnel compression. So, once I turned that off, it started working. :)

    Now, I just need to figure out why the WAN interface cannot do the DHCP renewal...

    A big thank you to Luk for all his help on this one!

    Cheers,

    Jens