Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site2Site VPN established, but Firewall blocking traffic

Hello folks,

I have succesfully established an IPSec Tunnel between an Astaro UTM 9 and a Watchguard Firebox XTM v. 11.7
The config looks like this:

(local) 10.20.100.0/24=10.0.88.200  (remote) 82.194.116.122=10.188.28.0/24

There seem to be two (probably different) problems here:

I can ping from local to remote, but not from remote to local.
When I try to ssh from local to remote, I can see the attempt being blocked by the firewall:

11:33:19 Default DROP TCP 10.20.100.144:33000 → 10.188.28.250:22 [SYN] len=60 ttl=64 tos=0x00 srcmac=0:50:56:8e:c:98

There is the default rule that should allow any traffic of type "Terminal Applications" from local networks to any destination, but this does not seem to apply.
I have tried rules additional rules in top position, that should allow this traffic to pass, but to no avail. I really hope someone out there can help me out.
Screenshots of the config are attached to this post.

Thanks to everybody.
playersons


This thread was automatically locked due to age.
Parents Reply Children
  • I don't know why you want WAN (Network) to communicate with nearly everything.

    Is your internal network something like 10.20.100/24?
    And which device is between your utm and the www?


    yes, that is our main internal network. We have a f5 load balancer between the utm (local network) and the www. there is a virtual server configured on the f5 that passes all traffic for a certain address to the utm.

    the WAN is actually just another local network on a seperate nic, that connects the utm with the f5.

    playersons
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?