Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Static route over SSL VPN

Network:

SiteA LAN 10.0.0.0/24, GW 10.0.0.1, Model XG210

SiteB LAN 10.1.0.0/24, GW 10.1.0.1, Model XG115

SSL VPN between SiteA and SiteB

Special VPN device located at SiteA, GW 10.0.0.9

 

So I'm at a bit of a loss whether or not this is even possible. From my last post with the Anti-replay issue, we had to get another device to handle a specific VPN.

I have created a static route at SiteA for all traffic pointed to the 192.168.99.0/24 network which is then routed to my VPN device on 10.0.0.9. This works great at SiteA. Perfect communication between peers. (Port1 is my LAN, it's connected to my core switch) 

 

The issue arises at SiteB. No one at SiteB can access the target host on the 192.168.99.0 network. This is normal since I never created a static route on the XG115 at SiteB. But you can't create a static route with your gateway on a different network than your interface. 

 

So is it possible to route traffic from SiteB over the SSL VPN to my VPN device at SiteA?



This thread was automatically locked due to age.
Parents
  • Hi Abhi,

    Add 192.168.99.0 in the local network on Site-A in the SSL S2S policy. Similarly, add the 99.0 network in the remote network on site-B. If that doesn't resolve the issue then, create a VPN > LAN rule and NAT the VPN traffic with your LAN network  and specify the gateway as 10.0.0.9.

    If the issue still persists, please show me a picture of your network interface configuration and SSL S2S policy.

    Thanks

  • That worked for me! Thank you. I'm assuming that for SSL VPN Remote Access I need to do a similar task and add my network to the Permitted Network Resources (IPv4) section?

Reply Children
No Data