Sophos UTM branch facility on static DSL: LAN at 10.142.0.0/16
Palo Alto VPN device at main office, on static fiber: LAN is 10.101.0.0/16
This works fine with Site-to-Site IPSEC and the two LANs can talk. Now from the Sophos LAN, we need to reach a mail relay server at an external IP address 199.98.x.x. That server is firewalled so only connections from the static fiber connection are accepted.
The proposed solution is to simply tunnel all the remote branch traffic over the VPN. According to Configuring an IPSec tunnel to send all traffic to a central UTM I should do this:
On the UTM at the remote site:
Navigate to Site-to-site VPN | IPsec | Remote Gateways.
On the defined remote gateway for the central office, click 'Edit'.
Change the 'Remote Networks' box to only contain the network 'Any'.
Click 'Save'.
When I do this (and I've removed the other entries in Remote Networks), the VPN tunnel instantly goes down and won't start up. I'm not sure of the Palo Alto VPN changes that need to be made to make all traffic tunnel.
I've also tried adding just the 199.98.x.x host as a host in the Sophos "Remote Network" list, and the VPN status screen shows it in red (not connected). The other remote networks still stay green.
Any ideas?
This thread was automatically locked due to age.