Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT through IPSec VPN

Hello,

 

I'm looking to port forward  between two sites through a IPSec VPN

We  have two sites connected through a IPSEC vpn.

 

             WANa                                               WANb

        ___|____                                           ___|____

       |   GW A  |    =======VPN =====    | GW B    |             

          -----------                                           ------------

                                                                          |

                                                                       DMZ

 

I've made the rules to open 443 port of a web server hosted in the DMZ of site B. I can reach the webserver from Site A and Site B LAN's,  and from  WANb public IP adress

I can't figure how to  make the  443 web server  reachable from WANa IP address.

 

Rule1  ( GW B )  -  SRC  WAN    -  DST DMZ  433          OK

Rule 2  ( GW A ) - SRC  LAN     -   DST DMZB 443          OK

Rule 3  ( GW A ) -  SRC WAN    - DST DMZB 443           KO

 

 

I've used packet capture.  Packets to WANa IP:443 match the business application rule, but the XG doesn't retransmit the request to  GWb.

I've tried enabling and disabling MASQUERADE, but nothing seems to be working.

 

Do you guys have any idea ?



This thread was automatically locked due to age.
Parents Reply Children
No Data