Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IPOffice SCN via two firewalls 1

Status
Not open for further replies.

iProfessor

Technical User
Nov 11, 2015
35
0
0
ZA
Hi All

I have two IPOffice 500's i need to join with SCN. Each IPOffice sits behind a Sophos xg firewall and there is a Sophos "RED" link between the 2 firewalls.

The route from one IPOffice to the other via the 2 firewalls is wide open, no ports blocked as it is inside a private network.

I cannot get the SCN to connect. it does not matter how i set the NAT on the firewalls.

Anyone have any ideas how to get this to work please?
 
Do you have a VPN between the 2 firewalls or are you trying to connect the IPO's to the public addresses of the firewalls?

you must have a VPN
Also We had one cust who tried to use software VPN solution that used PPTP that they simply could not get to work - installing Daytek routers @ each end with ip-sec VPN between them proved the issue was with the customers VPN solution.
the exact cause was never identified (cust stuck with the Drayteks :) )


Do things on the cheap & it will cost you dear
 
Hi IPGuru

The RED link is a Sophos proprietary vpn between the firewalls.

I am pretty sure that RED is neither pptp or ipsec
 
seems it doesn't work so use ipsec and it will work.
not much sense in troubleshooting if you can circumvent easier.

Joe W.

FHandw, just expired ACSS (SME)


"This is the end of the world, make sure to buy your T-shirt before it is too late"
Original expression of my daughter
 
iProfessor said:
The route from one IPOffice to the other via the 2 firewalls is wide open
iProfessor said:
it does not matter how i set the NAT on the firewalls.

Which one is it, NAT or routed?
There shouldn't be any NAT, especially if you use H.323 SCN link.

"Trying is the first step to failure..." - Homer
 
Hi Janni78

Have tried with no Nat at all, no joy
 
After what I can tell by looking around a bit a RED link is always "NATed".

"Trying is the first step to failure..." - Homer
 
I am trying an IPSec vpn now.

busy working through it
 
Hi All

Thanks for the help.

I created an IPSec vpn and all is working.
 
If they are within a private network why can't you just create a direct link between the two XG firewalls? No need for VPN...

I worked with a customer who had branches connected through sophos red boxes. IPO and IPBS could be reached from the main side so I think it must not be necessarily NAT.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top