Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

End to Site to Site or: How to?

Hello everyone,

I am planning to do a classic scenario, however, the FAQ and KBs don't help me at all.

My idea is as this



My Laptop --- VPN (L2TP) ---- my UTM ====== IPSec ==== my friend's UTM ----- his network



Seems easy, but what configurations do I have to do? What firewall rules, what NAT masking?

I appreciate your suggestions.


Regards


ZeroEnna


This thread was automatically locked due to age.
Parents
  • This KB article addresses your issue: How to allow remote access users to reach another site via a Site-to-Site Tunnel

    With L2TP, you shouldn't need anything other than to be sure you two have different Internal and "VPN Pool (L2TP)" subnets and then to add the appropriate Firewall rule on each side.

    Whenever someone uses a SNAT in this situation, I suspect that  there's been a violation of what I call Rule #3:

    Never create a Host/Network definition bound to a specific interface.
    Always leave all definitions with 'Interface: >'.



    DNS for Remote Access is configured in 'Remote Access >> Advanced'

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • This KB article addresses your issue: How to allow remote access users to reach another site via a Site-to-Site Tunnel

    With L2TP, you shouldn't need anything other than to be sure you two have different Internal and "VPN Pool (L2TP)" subnets and then to add the appropriate Firewall rule on each side.

    Whenever someone uses a SNAT in this situation, I suspect that  there's been a violation of what I call Rule #3:

    Never create a Host/Network definition bound to a specific interface.
    Always leave all definitions with 'Interface: >'.



    DNS for Remote Access is configured in 'Remote Access >> Advanced'

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?