Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connect external offices each others

Hello All,
We are migrating to Sophos SG330, I have some doubts because there is not corrispondence between Cisco Asa and Sophos.
I would like to permit to our branch offices to communicate each other. We use IPSEC VPN tunnel. I think I should create a natting rule between each of them, isn't right?
In practice (is a example):



EXTERNAL OFFICE 1        HEADQUARTER                 EXTERNAL OFFICE 2        EXTERNAL OFFICE 3
192.168.XX.XX                10.36.YY.YY                     192.168.ZZ.ZZ                172.16.XX.XX

I need that Office 1 can reach Office 2 and Office 3 and viceversa, obviously all offices must speak with headquarter :-)

Which Type of NAT I should use? Or, what should I do for let ours offices "talk"?

 

Thanks so much!
Alessandro



This thread was automatically locked due to age.
  • Hi Alessandro,

    Refer the guide here to configure IPSec on UTM. You need to add the remote networks in remote gateway configuration.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Alessandro,

    best is to avoid using NAT.. in your example you need nat so office 1 can speak to office 2.

    best is here to fix your networks.. e.g. use 192.168.1.0/24 for office 1 and 192.168.2.0/24 for office 2. No nat needed then.

    you need at least 3 ipsec-vpn-tunnels all from hq to the offices.

    also you can define a full meshed network so you need 3 ipsec-vpn-tunnels from each location to the others... depends on your needs and rules.

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Hi, Alessandro, and welcome to the UTM Community!

    Almost eight years ago, Gert Hansen, the initial creator of V1.0 of what is now UTM 9.4 answered this question in the German forum.  I summarized his response in that thread and then translated it to English here.

    No NAT is required or desirable.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks for helping me guys, I really appreciated.

    I know that is better to avoid NAT, but I can't change easily office's networks. I simplified the schema, but I have much more branch offices and some of these are production plant that can't be stopped.
    In this case, how can reach my purpose?
     
    Hace a nice day,
     
    Alessandro.
  • Hi,

    - define transfer net on office 1, choose a network for you dont use.. eg. 172.16.90.0/24

    - define SNAT on office 1 for traffic to office2 snatting to transfer net

    - ipsec tunnel from office 1 to office 2 must use transfernet in definition.

    then it is possible to communicate...

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Alessandro, if there are duplicate subnets in two offices, please edit your original post to show that.

    zaphod, there's actually a good KB that you can link to for folks needing your prescription: How to tunnel between two UTMs which use the same LAN network range.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?