Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Any" object overrides all others in SSL VPN local networks

So I've got a UTM appliance which exists only for VPN usage. Clients hit the external interface which is also the default gateway for the appliance, and I've got specific local networks setup in the SSL VPN config which go out an internal side NIC (static routes to another router). What I'd like to do is configure the SSL VPN to route all client traffic through it which was accomplished by adding the "Any" object to the VPN local networks, but after this was done the existing networks no longer worked as traffic to them was now trying to go back out the external default gateway.

The network objects for these existing SSL VPN local networks just have the interface option as "any" so I'm wondering if I change all of these to the internal NIC would that help this work... Similarly if I use the "internet ipv4" object instead of "Any" to catch all client traffic as it is configured for the external NIC instead. I would just experiment with these settings but I don't want to break client connectivity by doing tests.


This thread was automatically locked due to age.
Parents
  • Probably, just replacing "Any" with "Internet IPv4" will solve your problem.  If not, ...

    the external interface which is also the default gateway for the appliance

    The External interface is its own gateway?

    Please click on [Go Advanced] below and attach a picture of the Edit of your SSL VPN Profile.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Probably, just replacing "Any" with "Internet IPv4" will solve your problem.  If not, ...

    the external interface which is also the default gateway for the appliance

    The External interface is its own gateway?

    Please click on [Go Advanced] below and attach a picture of the Edit of your SSL VPN Profile.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data