Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec user VPN when Sophos is behind a load balancer

Good evening all!

 

We have the following configuration that I need to punch an IPSec client connection through:

 

ISP#1      ISP#2

  |               |

Peplink load balancer

           |

Sophos UTM

 

We currently have a functional SSL VPN connection for our remote users, but our CEO has requested better throughput and would like us to implement an IPSec VPN solution.  The configuration is straight forward, but my only options when selecting the connection are the Internal, External, DMZ, etc.  This puts the connection point behind the Peplink and, while we do have a NAT configured from a public IP in to the private IP on the external link of the Sophos, the connection can't resolve.

We can bypass the load balancer by plugging one of the ISP connections into a separate port on our Sophos, but that kind of defeats the purpose.  Is it possible to connect an IPSec VPN from a remote client with the above configuration or will we need to move one of our ISPs?

 

Thank you,

Steve



This thread was automatically locked due to age.
Parents
  • Hi Steve and welcome to the UTM Community!

    I don't know of an IPsec client that can be configured to deal with using an IPsec remote access server behind a NAT.

    How about a pic of the Cryptographic and Compression Settings on the 'Advanced' tab of 'SSL VPN'?

    I'd be tempted to get rid of the Peplink and let the UTM perform that function, so that the UTM has both public IPs.

    Cheers - Bob

Reply
  • Hi Steve and welcome to the UTM Community!

    I don't know of an IPsec client that can be configured to deal with using an IPsec remote access server behind a NAT.

    How about a pic of the Cryptographic and Compression Settings on the 'Advanced' tab of 'SSL VPN'?

    I'd be tempted to get rid of the Peplink and let the UTM perform that function, so that the UTM has both public IPs.

    Cheers - Bob

Children
No Data