Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing VPN Netz über anderes Netz

Hallo miteinander,

 

ich stehe vor folgender Herausforderung:

Site A (Sophos SG) ist via IPsec VPN zu Site B verbunden. Alle Netze sind gegenseitig erreichbar.

Nun haben wir einen Dienstleister Site C an unser Netzwerk Site A angebunden ebenfalls via IPsec VPN. Hier besteht nur Zugriff zwischen dem Netz von Site C und unserem Site A 192.168.4.X Netz.

Nun haben wir einen Server in Site B, der Daten an Site C senden muss. Site C erwartet natürlich, dass der Traffic aus unserem Netz 192.168.4.X kommt.

 

Funktioniert das so und falls Ja wie? Geht das über Policy Routing?

 

Danke schon mal vorab.



This thread was automatically locked due to age.
Parents
  • Entschuldiging für Antwort in English.

    You need to include 10.5.5.x subnet in the IPSec networks between site A and B so Site B knows to send this traffic to A.

    In Site A you need a SNAT rule where you translate traffic from Site B going to Site C to an IP-address in Site A (could be the interface IP-address from Sophos in Site A).

    You need to enable the option that this should also be valid for IPSec traffic.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • Thank you very much!

    I could not test it fully for now, because i have no access to the Firewall at Site B, but i tested it with one of our VLAN's and it worked good, so i think for the network at Site B it should be the same.

     

    Best regards

Reply Children
No Data