This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Configuration problem remote access to two networks

Hello

I run a UTM 9 and everything works quite well. But I have a question about a remote access configuration to two different networks over the same remote access connection.

Right now, I have a remote connection to the internal network (A) let’s say 192.168.23.0/24. This is accessible via the Sophos VPN Client and I can connect to the terminal server.

I also have a IPSEC connection to an external network (B) let’s say 10.10.100.0/24. The PC’s and Servers in B are member of the domain network of A and I can ping and RDP them from A.

My goal is to be able to have a remote connection to B as well and can RDP to a server in A and in B.

Sorry German speaker Slight smile

Can somebody help?



This thread was automatically locked due to age.

Top Replies

  • Okay, between A and B there is a IPSEC site-to-site connection.

    SITE-TO-SITE CONNECTION

    From Sophos (A) configure the site to site like that this:

    Local networks:

    • Intern net A network
    • VPN Pool Network (probably 10.242.2.0/24)
    • maybe also Intern net C and D if necessary

    Remote networks:

    • Net SDL B subnet

    From Net SDL (B) configure the site to site like this:

    Local networks:

    • Net SDL B subnet

    Remote networks:

    • Intern net A network
    • VPN Pool Network from site A
    • if necessary Intern net C and D

    SSL Remote VPN

    Configure the SSL VPN profile on Sophos with the following subnets:

    • Intern net A
    • Net SDL B
    • if necessary intern net C and D

    That should at least bring up all the VPN connections. If you tick Automatic firewall rule on both IPSEC and Remote SSL VPN that should also allow all traffic between all the subnets in Sophos.

    Check all subnets for non-overlap

    You must also check that you have no overlapping subnets, so check:

    1. Local subnet at the Client who makes Remote SSL connection
    2. Intern net A
    3. Intern net C
    4. Intern net D
    5. Net SDL B

    None of these must overlap otherwise there will be routing issues. If you don't know whether or not there is overlap, than you can put the subnets in use here so we can check for overlap.

    Jump to answer