This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect vs DNS

So i finished all the instructions as posted on page https://community.sophos.com/kb/en-us/133109

Downloaded the client and exported the configuration. Set up the client and finally made a connection.

So far so good. Can ping hosts on the internal network by ip adress, however i can't seem to reach hosts by their name.

I did enter the ip of the DNS server but somehow hosts aren't being resolved.

 

Any thoughts or pointers on this.

 

Thnx, Peter-Paul



This thread was automatically locked due to age.
Parents Reply Children
  • I'm having the exact same issue. The update didn't resolve it. It works fine with SSL VPN.

    When connected with the Sophos Connect Client, none of my domain resources work, like mapped drives and printers. I can log out of Sophos Connect and log in with SSL VPN and everything starts working.

     

    There is still something wrong with the client or there is something wrong with the configuration being pushed to the client from the firewall.

  • Second this, still not working for me, SSL VPN works great.

    Ended up uninstalling the Sophos Connect client. Will wait until there is somebody confirming correct functioning.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • I can work perfectly fine with the Connect client V1.2 

     

    Can you post some logs and screenshots of this issue? 

    __________________________________________________________________________________________________________________

  • Hello Leet,

     

    Can you please list the steps on what the settings are to make it work on SSL VPN. I would like to see why it is not working with Sophos Connect.

     

    Thank you,

    Ramesh

  • Hello Peter,

     

    Can you please list the steps on what the settings are to make it work on SSL VPN. I would like to see why it is not working with Sophos Connect.

     

    Thank you,

    Ramesh

  • Unknown said:

    Hello Leet,

     

    Can you please list the steps on what the settings are to make it work on SSL VPN. I would like to see why it is not working with Sophos Connect.

     

    Thank you,

    Ramesh

     

    I haven't had a single minute to try and diagnose this further yet and I'm not comfortable posting the logs publicly with company info in them.

     

    SSL VPN works with nearly the exact same settings as Sophos Connect.

     

    Neither work for domain resources initially. When I try to go to \\server.domain.local it doesn't work. None of my network drives can connect either.

     

    HOWEVER, on the SSL VPN, On the XG admin webpage, I have to go to "Show VPN Settings" >>> "SSL VPN" and specify "Domain Name" as "domain.local"

     

    After doing that, SSL VPN works for domain resources, however, Sophos Connect does not and doesn't have a setting for me to specify a domain.

  • Thank you Leet for this information. Have you tried out the suggestion from Emile? Please let us if that works.

     

    Ramesh

  • What is the correct way to handle dns suffix search in Sophos Connect vpn for users to reach internal systems by hostname on their own personal devices we can't touch with gpo without manually adding internal domains to dns suffix search list?

  • Hello Momentum,

     

    In the Sophos Connect Client policy you configure on XG, you will assign the DNS server 1 and DNS server 2 (if available). After the tunnel is established, all hostname look ups will be sent down the tunnel and the internal DNS server should resolve the internal systems by hostname.

     

    Please let us know if this works for you.

    Ramesh

  • Hi Ramesh

    Configuring the DNS servers is only part of the requirements for friendly name resolution. You also need to be able to configure the DNS suffix (or better, a list of suffixes) for the connection. Configuring the suffix list to include "example.com" allows someone to connect to the server "server01.example.com" using just the short name server01. The configured DNS suffix is automatically added to the end of the name if the name is incomplete.

    Most VPNs do this automatically - but the lack of documentation on the TGB and SCX file formats means we can't reverse-engineer it easily, and it's not exposed in the firewall or admin UIs.

    It's also worth noting that at least for me, I had to manually create a firewall rule to permit communication from the VPN to the internal networks - it wasn't automatically provisioned when I completed the Sophos Connect configuration on the firewall.