Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Branch office move: remote IP changing

What happens to a site-to-site VPN when one of the end point IPs changes?

One of our branch offices is moving to a new location, and will change its external IP. We have an IPSec site to site VPN set up from our main offices to the branch office, which used X.509 certificates for authentication, and the VPN ID type is fqdn. Obviously, the VPN will break when the branch office's IP changes, but will this be easily fixable? That is, can I just update the IPs in the definitions used in the remote gateways secction, and have the VPN spring back to life again, or is it more complicated than that?

Would it be simpler just to scrap the current VPN setup, and create a new one once the IP has changed? 

Any advice gratefully received!



This thread was automatically locked due to age.
  • Hi Davies,

    Turn of the IPSec policy on both end, change the remote and local end gateways and turn ON the policy. It should work easily.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Like Sachin says and you suspect, just change the IP and disable/enable the IPsec connection.  If the Remote Gateway in the branch is set to 'Initiate connection' and the one in the main office is set to 'Respond only', you have nothing to change and the new branch location will come online immediately after the UTM boots up.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks,  Sachin and Bob.

    It's one of those jobs where you think "Naaaah! It can't be that simple! What am I missing?", when in fact it IS that simple...

    All the best

    Ifor