Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FXB
Contributor

VPN Routing on SMB Appliance with domain-based VPN

Hi folks,

we are trying to set up a VPN connection to a service provider of our company currently. 

Since that company is not able/does not want to define VTIs on their Sophos XG, we need to set up a "classic" VPN Tunnel via Domain-based routing.

The endpoint on our side is a dedicated 1450 checkpoint SMB appliance, running on R77.20.85 and is used just for VPN termination with only IPSec VPN Blade enabled.

We configured the interoperable device with the encryption domain as well as the VPN community. The Tunnel is up and working, SAs are available on both sides and looking at the VPN monitoring on the WebGUI of the 1450 it also shows the Tunnel up.

However when we try to access resources in the encryption domain , we see that the packets do not get routed into the tunnel/community but rather exits the default route to Internet where it gets dropped of course.

With our openserver checkpoint running on R80.10 we never had the problems, that the gateway is not routing the packets into the tunnel when we defined such a VPN tunnel.

Is there something we need to consider/change when setting up a VPN connections with the SMB Appliances?

Any help is appreciated.

Regards,

0 Kudos
6 Replies
G_W_Albrecht
Legend Legend
Legend

I would suggest to put this in the SMB Appliances and SMP corner...

Please look in VPN Site-to-Site with 3rd party

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Jerry
Mentor
Mentor

$FWDIR/lib/crypt.def  ?

Jerry
0 Kudos
Jerry
Mentor
Mentor

--sk86582--
Jerry
0 Kudos
FXB
Contributor

@G_W_Albrecht your right, i should have posted it in that section, i cant move the post after the creating as it seems (or i dont find the option) unfortunately.

@Jerry Thanks for providing the SK. Unfortunately from what i read so far it describes how to exlude specific subnets from VPN routing. Our problem is that they dont get included in VPN routing in the first place.

I am go ahead and have a look at the article @G_W_Albrecht posted if there is sth useful for us.

0 Kudos
PhoneBoy
Admin
Admin

Only admins can move posts. I've taken care of it.
0 Kudos
HristoGrigorov

Locally or centrally managed appliance? Either way make sure the relevant rule is set to encrypt in the proper community.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events