Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN can't reach any device on LAN.I know it's has been discussed a lott, but I can't figure out what wrong. Please help.

Hello,

 

I installed the sophos XG 125 a few days ago. So far everyting works fine except I can't get access to any device on the LAN via SSL VPN. I have been reading through a lott of topics, done all the youtube tutorials. My configuration seems just fine.  I can't ping my server on 10.20.3.181 from a VPN connected client that has been assigned a IP of 10.81.234.6. 

The VPN client connects just fine also using internet through the VPN is working when in full tunnel mode.

 

I have added all the needed firewall rules:

- LAN to LAN

- VPN to LAN

- LAN to VPN

- LAN to WAN

I have bridged the all the ports except the port 2 used for WAN:

My  SSL VPN connection, adding all interfaces to the permitted network resources, also the bridge called "switching":

 

My VPN settings:

 

 

any help would be more than welcome.



This thread was automatically locked due to age.
  • Still can't figure it out. Been busy testing all kind of settings.

     

    Firewall rules:
    ------------------------
     
    Rule 1 LAN to VPN:
    source: LAN
    destination: VPN
    Service: Any
    Match known users: not selected
    NAT & Routing: default
     
    Rule 2 VPN to LAN:
    source: VPN
    destination: Any
    Service: Any
    Match known users: not selected
    NAT & Routing: rewrite source address (Masquerading)
    Use Outbound Address: MASQ
     
    Rule 3 LAN to WAN:
    source: LAN
    destination: WAN
    Service: Any
    Match known users: not selected
    NAT & Routing: rewrite source address (Masquerading)
    Use Outbound Address: MASQ
     
    Rule 4 LAN to LAN:
    source: LAN
    destination: LAN
    Service: Any
    Match known users: not selected
    NAT & Routing: default
     
     
     
    Network:
     
    Port 2:
    Wan configured with gateway
    working fine
     
    Bridge called "Switching"
    Member interfaces:
    interface: port 1 zone: LAN
    interface: port 3 zone: LAN
    interface: port 4 zone: LAN
    interface: port 5 zone: LAN
    interface: port 6 zone: LAN
    interface: port 7 zone: LAN
    interface: port 8 zone: LAN
     
     
     
    SSL VPN:
     
    Policy members:
    - added all users and groups
     
    use as default gateway: on
    permitted network resources (iv4):
    #port1
    #port2
    #port3
    #port4
    #port5
    #port6
    #port7
    #port8
    #switching   (bridge)
     
    SSL VPN settings:
     
    IPv4 Lease range: 10.81.234.5 - 10.81.234.55
    Subnet mask: /24
    lease mode: IPv4 only
     
     
     
     
    DHCP:  (working fine)
    Interface: Switching - 10.20.3.254
    Dynamic lease: 10.20.3.100 - 10.20.3.180
    static IP  mac address: xxxxxx     ip adress: 10.20.3.181  (server)
     
    subnet mask: /24
     
    Gateway: "use interface IP as Gateway"
     
    DNS: user device DNS settings
     
    DNS: (working fine)
    static DNS
    DNS 1: xxxxxx
    DNS 2: xxxxxxx
  • Hi Robin,

    Two quick checks:

    1. VPN to LAN rule, MASQ enabled.

    2. Allow access to SSL VPN on the LAN zone from Administration | Device access | LAN > SSL VPN.

    Any help?

  • yes both where already set

     

    1. VPN to LAN rule, MASQ enabled:

     

    2. Allow access to SSL VPN on the LAN zone from Administration | Device access | LAN > SSL VPN.

     

  • Got the solution with a little help from some one that should be on holiday ;)

     

    The problem for me was that I added the interfaces(port1,port3 etc) for allowed resources. What worked for me was that I added IP network and subnet!  

     

     

     

     There is also a bug. Adding an IP range won't work, it will show you a green message it was added but it will not add it to the permitted resources.

  • I will get this updated in the KBA. 

    Thanks for the update