Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG not support masquerading without a valid alias or primary IP

Hi all,

I'm bewildered about an XG's behavior ... A customer need to masquerade an entire network with a different IP range and  navigate with a remote gateway. The schema will explain more clearly

 

 

Now i've already configured the correct rules, the issue is with masquerading. If i do it with a single IP and create an alias on the network interface attached to the 10.0.x.x network all works fine, but if masquerade with an IP range (it's a valid option in the maquerading's definitions interface) and i DON'T create all alias for the ip in the range the XG don't accept the reply packets for the communications generated from an IP in the range ... So my question is: if it's an unsopported scenario, why i can use an IP range in the masquearding rule? otherwise i must create 200 alias? really???? 

 

SG ... i miss u so so much :(



This thread was automatically locked due to age.