Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec and SNAT Routing

Hi,

I did setup a VPN Tunnel to a customer, which is running fine so far. We are required use SNAT for our local IP addresses (only our side).

Until now I see in the firewall log the white lines that the snat rule is used for the specified source hosts and I also see a green line, that this traffic is allowed.
But it seems that the traffic isn't routed through the tunnel. I used the espdump command (described here: https://support.sophos.com/support/s/article/KB-000034339?language=en_US ) to check this and don't see any packets in the tunnel. Also the customer confirmed  he doesnt see any packets comming from us.

I found much posts about snat and vpn but not regarding routing except this one:
https://community.sophos.com/utm-firewall/f/vpn-site-to-site-and-remote-access/51437/vpn-ipsec-snat-and-routing-problems

But this is 17 years old and the files mentioned there also do no existing anymore, but it would explain the problem.

Can anybody help how to force this traffic through the tunnel?
I also checked the routing table , that there is no other route to smae target network.



This thread was automatically locked due to age.
Parents Reply Children
No Data