Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multiple S2S VPNs between two UTMs

Hello everyone,
we are having multiple sites equipped with UTMs

Now one of the sites which previously just had a local LAN added a local DMZ network to its IP ranges.

The site is/was connected to HQ using a S2S with automatic firewall rules

Site-Lan <> Any <> HQ-networks

Now I would like to add the second remote range as well but obviously not with Automatic firewall rules

So I thought to just create a second S2S tunnel with manual firewall rules

Site-DMZ <> HQ-networks + rule that specifically allows certain services to be accessed from HQ in Site-DMZ but no access from Site-DMZ to HQ-networks

Configuration wise both UTMs use Hostname as VPN-ID and have RSA-Keys exchanged
The second S2S would be auto-firewall-rule on Site-side and manual on HQ-side

Would this work or would I get trouble with SAs not being assigned correctly or soforth?

Site-LAN and Site-DMZ are separate ranges w/o overlap

Thanks for your help



This thread was automatically locked due to age.
Parents
  • I think we may not "see" your situation, Ingo.  I just read through it twice and, since there are no diagrams with IP ranges for the existing and proposed tunnels, I'll just assume that none of the following subnets overlap: {HQ LAN}, {HQ DMZ} & {Site LAN}.

    If the first tunnel is '{HQ LAN}<-[Auto Firewall Rules]->{Site LAN}', it is possible to create a second tunnel '{HQ DMZ}<-[Manual Firewall Rules]->{Site LAN}'.  As apijnappels suggests, it's also possible to make a new firewall rule like '{HQ LAN & Site LAN} -> Any {HQ LAN & Site LAN} : Allow', disable Auto rules in the IPsec Connection and then make the specific rules you want between {HQ DMZ} {Site LAN}.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I think we may not "see" your situation, Ingo.  I just read through it twice and, since there are no diagrams with IP ranges for the existing and proposed tunnels, I'll just assume that none of the following subnets overlap: {HQ LAN}, {HQ DMZ} & {Site LAN}.

    If the first tunnel is '{HQ LAN}<-[Auto Firewall Rules]->{Site LAN}', it is possible to create a second tunnel '{HQ DMZ}<-[Manual Firewall Rules]->{Site LAN}'.  As apijnappels suggests, it's also possible to make a new firewall rule like '{HQ LAN & Site LAN} -> Any {HQ LAN & Site LAN} : Allow', disable Auto rules in the IPsec Connection and then make the specific rules you want between {HQ DMZ} {Site LAN}.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data