Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN on XG firewall with Dynamic IP address, intermittent connection

I have Sophos XG 17 set up.  I created SSL VPN connection, and logged into user portal to download the config file for use on OpenVPN.  I'm currently using iPhone.  I noticed the file name on the config file indicates the public IP currently I'm at.  Upon connection, within seconds, I'm able to access resources immediately.  On another occasion, I tried to connect once again, this time, it seemed to take over 2 minutes to connect.  But upon connection, I can still access resources.  There is an option to override the server address, in the openvpn config.  Since I have my firewall configured using Sophos service for dynamic dns, upon putting the Sophos provided FQDN, I'm able to connect within seconds once again.  I tested this several times.  Without using Sophos FQDN, it connects very slow.  I also noticed that my public IP address has changed since I generated the config file.  The public IP address seen on the config file during initial download is no longer my current IP address.  Is this the reason it's taking a long time for client to connect to Sophos Firewall?  If so, is it ok if IP address keeps on changing?  I don't need to download new config file every time, just overide it with Sophos provided FQDN?

How do I do this in TunnelBlick (Mac)?  I download the config file for Mac, I get connected, but it takes the same 2 minutes or so.  Unfortunately, I don't know if it's possible to put server address onto TunnelBlick config.  I can't see how.  Hope others can shed light on this.



This thread was automatically locked due to age.