SOLVED

VPN multi site azure to UTM 9 with policy based / Problem with route based on UTM 9

%3CLINGO-SUB%20id%3D%22lingo-sub-2078445%22%20slang%3D%22en-US%22%3EVPN%20multi%20site%20azure%20to%20UTM%209%20with%20policy%20based%20%2F%20Problem%20with%20route%20based%20on%20UTM%209%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078445%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI%20have%20two%20Sophos%20UTM%209%20firewalls%20installed%20at%20two%20different%20sites.%3C%2FP%3E%3CP%3EI%20started%20the%20configuration%20of%20an%20azure%20to%20UTM9%20VPN%20on%20site%201%20with%20root%20based%20but%20it%20doesn't%20work%20and%20I%20found%20information%20in%20the%20Sophos%20community%20that%20UTM%209%20does%20not%20support%20route%20based%3CBR%20%2F%3Ebut%20it%20only%20supports%20the%20policy%20based.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EIs%20there%20a%20solution%20for%20the%20policy%20based%20to%20support%20the%20mutli%20site%3F%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThanks%20for%20your%20help.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

I have two Sophos UTM 9 firewalls installed at two different sites.

I started the configuration of an azure to UTM9 VPN on site 1 with root based but it doesn't work and I found information in the Sophos community that UTM 9 does not support route based
but it only supports the policy based.


Is there a solution for the policy based to support the mutli site?


Thanks for your help.

2 Replies
Best Response confirmed by hamma91 (Occasional Contributor)
Solution

@hamma91 

 

Hi  

 

You can go with policy based but it's not suitable for only  many  sites according to the documentation . 

Also you cannot forward a request from one site to another using the VPN gateway . 

 

The question is : does the sites need to communicate each other through the gateway ?

 

https://docs.microsoft.com/fr-fr/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps

 

You can also create an Network Virtual Apliance to create your S2S connection instead of using  VPN Gateway .

@ibrahimambodji  thank you very much Ibrahim 

following your advice, I created a forti on azure then I made ipsec VPN with the other sophos UTM 9