所以我根据这个文件配置Sophos的XG站点到站点VPN: https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/sfos /learningContent/VPNCreateRouteBasedVPN.html
但是我遇到了以下问题:SiteA:Branchoffice,LAN 192.168.198.0/24 SiteB:Headoffice,LAN 172.30.0.0/24 如果我从 Site-A ping 到 Site-B,在 ping 时 Sophos-A 上的 tcpdump 会显示这个穿过去:
18:53:04.059527 Port1, IN: IP 192.168.198.244 > 172.30.0.3: ICMP echo request, id 46946, seq 0, length 64
18:53:04.059737 xfrm1, OUT: IP 192.168.198.244 > 172.30.0.3: ICMP echo request, id 46946, seq 0, length 64
18:53:04.069119 xfrm1, IN: IP 172.30.0.3 > 192.168.198.244: ICMP echo reply, id 46946, seq 0, length 64
18:53:04.069193 Port1, OUT: IP 172.30.0.3 > 192.168.198.244: ICMP echo reply, id 46946, seq 0, length 64
如果我从站点 B ping 到站点 A,tcpdump 会在 Sophos-B 上记录以下内容并且 ping 不通过:
18:53:21.509216 Port4, IN: IP 172.30.0.3 > 192.168.198.244: ICMP echo request, id 2025, seq 1, length 64
18:53:21.509354 xfrm1, OUT: IP >WAN-IP< > 192.168.198.244: ICMP echo request, id 2025, seq 1, length 64
为什么从站点 A 到 B 它xfrm1, OUT: IP 192.168.198.244(如预期的那样)而从站点 B 到 A 它是xfrm1, OUT: IP >WAN-IP<
我只是不明白为什么它使用从 B 到 A 的 WAN-IP,但反过来它采用正确的路径?
欢呼