Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Astaro SSL vpn access users to reach another site via a Astaro v8.309 & ASA v7.2(4) S

Hello Team,
 
I have Astaro & ASA IP-sec connection & it's working fine.
 
Now i want to connect Astaro SSL user with different IP pool range to connect to the ASA Lan via Astaro - ASA Ipsec tunnel.
 
Below is the change i have done so far , but it's not working.
  
Please find the attached diagram of the setup.

I have already referred the below article for the same

How to allow remote access users to reach another site via a Site-to-Site Tunnel

Am i missing something ??
 
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Site 1 = Astaro LAN Pool => 192.168.21.0/24
Site 2 = Astaro SSL Pool => 10.120.2.0/24
 
ASA Lan Pool => 192.168.1.0/24
 
@ Astaro => 1) Added the ASA Lan Pool in the local pool of the astaro SSL user.
                    2) Added the Astaro SSL pool in the IPSec Local pool with the Astaro Lan Pool.
                    3) And click on the automatic firewall rule.
 
@ ASA => 1) Add the Astaro SSL pool with the remote lan pool with the Astaro Lan pool
                 2) Add the no nat(exempt) rule Interface=> Inside for source=> ASA Lan pool To destination => Astaro SSL pool


This thread was automatically locked due to age.
Parents
  • What indicates that you aren't connecting?  If it's pinging, then, beginning in V9, you need a Firewall rule to allow inbound pings - the 'ICMP' tab only regulates outbound pings.  Agreed that SNAT should not be necessary - that would indicate a misconfiguration elsewhere.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • What indicates that you aren't connecting?  If it's pinging, then, beginning in V9, you need a Firewall rule to allow inbound pings - the 'ICMP' tab only regulates outbound pings.  Agreed that SNAT should not be necessary - that would indicate a misconfiguration elsewhere.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?