Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rules for foreign VPN

Hello,

 

I am running a dedicated VPN server to test Wireguard.

My current network for this looks like:

[Sophos XG] === 192.168.12.0/24 === [VPN Server] === 192.168.80.0/24 [VPN Devices]

 

My general firewall usually consists of LAN/VPN Allow/Deny Any - but I am not sure how to add my Wireguard network to the VPN list.

Is there a way to do this?

 

Or is Sophos using the rules which are valid for my 192.168.12.0 subnet?

 

Thanks,

Mathias



This thread was automatically locked due to age.
Parents Reply
  • Do you use VPN (IPsec) with Wireguard and which mode? Routebased or Policy Based? 

    In Routebased, you would simply route the traffic to the other site through the tunnel.

    In Policy Based you have to configure the local network and the remote network and the XG will take action for the routing.

    Be aware of the routing precedence on XG. https://community.sophos.com/kb/en-us/123610

    VPN means "Policy based". 

    __________________________________________________________________________________________________________________

Children
No Data