We're replacing our Juniper with a UTM and we had to roll back last weekend because two different VPNs failed. This thread is about the second VPN.
It's an IPsec VPN that terminates on the UTM. The VPN showed "Up" on both ends but inbound traffic did not move to our internal server. In addition, I could not ping the remote end from our server. I can ping when we're running the VPN through our existing Juniper firewall.
Juniper and Sophos seem to do everything differently, so I'm retraining myself with every step. On the Juniper, the VPN is called a tunnel and it is it's own interface. Within that interface an IP is NATted to our internal server IP. I suspect that this is what I'm missing on the Sophos. Do I just add this as an "additional address" with a new NAT rule, like anything else? If it matters, the IP is not part of our normal block, but /30 block our ISP is providing us for this address.
This thread was automatically locked due to age.