Hello all, recently installed Sophos. I needed to replace my aging ASA 5505 at home due to some limitations with the base license and the hardware cap of 100 Mbps interfaces. I tried a few vm based firewalls, but think I would like to settle on Sophos.
I have most things working the way I want, except for remote access vpn. I was finally able to make a connection and I can access LAN resources fine, but I have no Internet while doing so. I seem unable to access my regular DNS server. If I do an nslookup from the command line specifying the utm as a resolver, it works fine. But I don't see how to assign that to vpn client sessions. I do have the ipsec vpn pool allowed to use the utm as a resolver, so it's not that. I don't see anything being dropped in the firewall log and the ipsec log looks pretty clean as well.
Is there a way to split tunneling or something so that I use the ipsec tunnel only for remote LAN traffic and continue to use my local resources and web gateway? That was how things worked with my ASA, and I would not like to be locked into connecting only to the remote LAN for everything. I use this vpn session primarily from work. I have a large esx lab that I run virtual routers, and LTM appliances, etc, that I use on a daily basis. If I am cut off from accessing the corporate network while using the Sophos ipsec vpn, then that's pretty much a deal breaker. So, I really hope that is not the case.
Thank you!
This thread was automatically locked due to age.