Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to site VPN (SSL) with default gateway?

Hi,

I have a SSL site-to-site VPN connection between headquarter and branch office.
What do I need to set to get ALL traffic from branch office routed through headquarter GW? I cannot find a "default gateway" option.

Thank you very much for help,
Alex



This thread was automatically locked due to age.
Parents
  • Hi Alex,

    Depends on where you've configured the SSL Connection.  Either put "Internet IPv4" into 'Local Networks' in the main office or into 'Remote Networks' in the branch and then reload the new client in the other site.  Using "Any" should work, but, in my experience, using it can cause problems.

    Cheers - Bob

  • Hi BAlfson,
    thank you for your answer!

    What do you mean by "then reload the new client in the other site"? Just switching off the branch office connection and turn back on? Or create a new connection with the downloaded .apc file? I ask, because it is not working with putting "Internet IPv4" into 'Local Networks' in the main office.

    The connection was made long time ago, so I don't remember what I did exactly, but as long as I'm not a professional, I think I just configured the server/headquarter connection and downloaded the configuration .apc and installed it in the branch office UTM.

    Is above also correct for a IPsec VPN connection (2x UTM with IPsec VPN and BO should use HQ's GW)?

    Thanks a lot,
    Alex




  • Yes, Alex, "create a new connection with the downloaded .apc file" and it sounds like you did that.  Please insert a picture of the Edit of the Server definition.

    Cheers - Bob




  • So, the new SSL connection can be established, but no traffic is possible, neither to resources on HQ network nor internet access. What else do I miss?

  • If you downloaded the "configuration for remote tunnel endpoint" and installed it in your home UTM, I don't see why this won't work.  How about a picture of the Edit of the home 'Client' Connection...

    Cheers - Bob

  • Not too much to see here. This is the freshly imported file from HQ.
    Maybe a firewall rule?
    Better chance with IPsec?




    UPDATE: now I established an IPsec connection also. It seems to be more performant, so may be I should move from SSL to IPsec site2site anyway. Would the procedure be the same for IPsec to use the HQ UTM as default gateway (not to forget, both UTM's are behind an ISP's router)?

    ATM I don't have physical access to the HQ UTM, I'm currently connected through a OpenVPN client on my notebook over UTM's SSL Remote Access. So I need to be very careful with dis-/enabling firewall rules etc., because I don't want to kick me out of the UTM's.


    Best regards, Alex


    added UPDATE
    [edited by: GerdMehsel at 2:19 PM (GMT -7) on 29 Mar 2022]
Reply
  • Not too much to see here. This is the freshly imported file from HQ.
    Maybe a firewall rule?
    Better chance with IPsec?




    UPDATE: now I established an IPsec connection also. It seems to be more performant, so may be I should move from SSL to IPsec site2site anyway. Would the procedure be the same for IPsec to use the HQ UTM as default gateway (not to forget, both UTM's are behind an ISP's router)?

    ATM I don't have physical access to the HQ UTM, I'm currently connected through a OpenVPN client on my notebook over UTM's SSL Remote Access. So I need to be very careful with dis-/enabling firewall rules etc., because I don't want to kick me out of the UTM's.


    Best regards, Alex


    added UPDATE
    [edited by: GerdMehsel at 2:19 PM (GMT -7) on 29 Mar 2022]
Children