I'm working on a company that has two sites and they are connected through a Site to Site VPN. I have added a web filtering license to the "main" site and is working correctly as a transparent proxy using the Astaro Authentication Agent (we could not use standard proxy because of issues with some sites). However the remote site now has unlimited internet access directly out that sites Astaro. I need to route their internet through the VPN tunnel and through the main Astaro that has web filtering.
I tried to figure out everything I could from this post: https://community.sophos.com/products/unified-threat-management/astaroorg/f/58/t/53174 and this post https://community.sophos.com/products/unified-threat-management/astaroorg/f/58/t/54601 but still kinda stuck. So far I have:
On the Main router (internet access) - Network A
- added Network B to the allowed networks for web filtering.
- added Network B to the Local Networks under IPS
- added a masq rule for the Network B -> Uplink Interfaces
On the Remote router - Network B
- added the main DNS server for the domain
- added the AD server
- joined it to the domain (successfully)
- added the same users and group so they are identical
From here I thought I could just create two policy rules on the Network B router, one for HTTP and one for HTTPS, that would be gateway rules and forward the traffic to the Network A Astaro but it doesn't seem to be working (when I turn on the rules I see no traffic in the web filter log from that subnet). If I can't do this I suppose I can route all traffic (not much else would be going out anyway).
So the first question is how can I go about setting this up correctly so web traffic can be routed over the VPN and out the "main" router. Secondly will the Astero Agent work in this configuration?
-Allan
This thread was automatically locked due to age.