Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DMZ, VPN Client, Routing, FW

DMZ, VPN Client, Routing, FW

 

 

Hello,

 

I would like to setup a router (VPN Client) in a DMZ and route traffic from LAN over DMZ to Open VPN Tunnel. I have the following configuration till now:

 

WAN Interface (Ethernet) : 82.x.x.x

LAN: 192.168.0.0 /24

DMZ: 10.0.0.0 /8

 

 Ping and Web Access to DMZ Router are working. 

 

Firewall Rules for DMZ:

 

LAN to DMZ / Services http, https and ping allowed

 

Interesting for me is, that when i deactivate this rule, I’m still able to reach the routers web interface via https?

 

 

 

If i want to establish an vpn tunnel with the router in the DMZ, do i need a separate masquerading rule.

 

At the moment i have the rule LAN to External (WAN), do i also need DMZ to External (WAN)??

 

 

 

When i want to route specific traffic over the tunnel, lets say http / https, what kind of firewall rules / configuration i need?

 

Is there a way to split the traffic, and route specific requests to a public website direct, without going over the tunnel?

 

 

Any help would be highly appreciated.

 

 

 

Thanks

Sally



This thread was automatically locked due to age.
Parents
  • Also I would like just allow specific services from LAN to DMZ and DMZ to LAN, do I have to create a Rule like DMZ to LAN Block all, and add a separate Rule after like DMZ to LAN https, http ??

     

    Thanks a Lot!

    Sally

  • Can somebody help me out?

    Thx.

    Best regards

  • Hi Sally and welcome to the forum.

    You're asking a lot of different questions in just one thread. It is advisable on the forum to ask 1 question per thread to keep everything clear also for future visitors who might be searching for prolems alike.

    I will try to answer some of your questions though.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply
  • Hi Sally and welcome to the forum.

    You're asking a lot of different questions in just one thread. It is advisable on the forum to ask 1 question per thread to keep everything clear also for future visitors who might be searching for prolems alike.

    I will try to answer some of your questions though.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Children
No Data