Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't access Network resources when in VPN

Hello Guys,

 

Please Help me i'm really out of ideas, i'm new on sophos..and the job mus be done as soon as possible....here is my situation: we have two sites in my company linked with fibre ( LAN), we have a cisco firewall on site B and an XG430 on site A, site B has its internet from site A as this one is much faster, so all traffic is redirected to xg firewall whatever the traffic, on site A side we have an mpls ( verizon) which links us to an other country..when in lan i can access site B and the other country, and internet, no problem, but when in vpn or in site B i can't access the other country servers but i can access internet, and sites resources i will try to give you as much inofrmations i can to be able to understand, i have static routes on xg which redirect traffic going to the other country on to the gateway of the mpls.

 

 

 

 

                                                                                                                                                                                                                               

                                                                                                                                                                                                                                                                                                                                                                                                                                         

FYI : We have a firewall in site A because we want to build a vpn site2site if the LAN link goes down

 

Thank you in advance



This thread was automatically locked due to age.
Parents Reply Children
  • Amine,

    connect to XG console, option 4 and type:

    drop-packet-capture "x.x.x.x" where x.x.x.x is the source ip of a computer in site B that is trying to access the remote country network.

    Regards

  • Luk,

     

    Thank you very much taking the time to help me, i really appreciate it...drop packet doesn't give anything!

     

     

    can you please explain this part : Also make sure the firewall rule from site B to 172.16.253.53.x includes even site B

  • Amine,

    your traceroute should return first 192.168.99.2, which is the gateway of site B.

    If there is an asymmetric routing issue/firewall rule missing, you should see dropped traffic from drop-packet-capture command.

    Something is missing.  Make sure the remote computer you are testing on, has Cisco as default gateway.

    Regards

  • Luc,

    I agree with you something is missing, but what ? i don't have a clou i checked everything, yes the machine i'm using to try access remote country has the right gateway.

  • Amine,

    in site B why the devices are using the 172.22.65.1 as gateway? They should use the ASA as gateway....Something is missing or misconfigured. Can you share an output of traceroute www.google.com from site B machine?

    Thanks

  • Luc, 

    172.22.65.1 is the ASA interface i just forgot to put it beside the firewall icone on the net map, my fault.

     

    Here is the output

     

    C:\Users\!amine>tracert www.google.com

    Tracing route to www.google.com [172.217.23.36]
    over a maximum of 30 hops:

    1 <1 ms <1 ms <1 ms 192.168.99.1
    2 <1 ms <1 ms <1 ms my public IP [my public IP]
    3 1 ms <1 ms <1 ms 90.67.15.185
    4 * * * Request timed out.
    5 * * * Request timed out.
    6 * * * Request timed out.
    7 * * * Request timed out.
    8 * * * Request timed out.
    9 * * * Request timed out.
    10 * * * Request timed out.
    11 * * * Request timed out.
    12 * * * Request timed out.
    13 * * * Request timed out.
    14 * * * Request timed out.
    15 * * * Request timed out.
    16 26 ms 25 ms 26 ms lhr35s02-in-f4.1e100.net [172.217.23.36]

    Trace complete.