Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN - Cannot get it to work

Hi Guys,

Im at my wits end with this one, and would greatly appreciate some help.

XG125 - FW 18.0.0

I am trying to get the SSL VPN setup and for the life of me just cannot get it to work.

My network is as follows. WAN -> ISP MODEM -> XG. Important to note the ISP modem doesn't have bridge mode, I've been looking at replacing it but trying to find one thats compatible with NBN here in Australia with DHCP instead of PPPoE that has bridge mode is proving difficult but thats another story..

So because the ISP modem doesn't have bridge mode, instead it is simply set to forward all ports to the XG. Because the XG sits behind the modem, the XG gets a WAN IP 192.168.0.2 address from the DHCP server on the ISP Modem. To counteract this issue with the VPN in VPN settings i have used the Override hostname and put in the static WAN IP assigned by the ISP.

I have setup a test user (myself) configured the VPN policy as per the Sophos Guide and put the Bridge interface that has all the LAN ports as Permitted resource.

I have created a firewall rule VPN_LAN -- Source: VPN          Source Network: Any                Destination Zone: Any          Destination Network:Any        Match Known Users: Added the test user account

I have a blanket unlinked NAT Rule - Source: Any    Service: Any    Destination: Any Host         Trans Source: MASQ     Service:Original      Destination:Original     Inbound: Any    Outbound: Port 2 (WAN)


I have downloaded the SSL Client and the config, but it simply will not connect. It just continually times out. Looking in the firewall logs, its not even registering any attempts either.

Does anyone have any ideas?








 



This thread was automatically locked due to age.
Parents
  • Hello, Shane.


    Check if the SSL VPN is allowed for the WAN in the Device Access. It's located in System > Administration > Device access.


    Also make sure if the port 8443 is not blocked by your provider. If so, you can change it at the same place that you override the hostname.


    You also can right click in the VPN SSL Client and "show status". It should give you more information about the connection and where it's failing.




    And if you override the hostname after download the config, delete the old profile (C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config) and reinstall it.

     

    Att,

    Rafael

Reply
  • Hello, Shane.


    Check if the SSL VPN is allowed for the WAN in the Device Access. It's located in System > Administration > Device access.


    Also make sure if the port 8443 is not blocked by your provider. If so, you can change it at the same place that you override the hostname.


    You also can right click in the VPN SSL Client and "show status". It should give you more information about the connection and where it's failing.




    And if you override the hostname after download the config, delete the old profile (C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config) and reinstall it.

     

    Att,

    Rafael

Children
  • Hi Rafael,

    Thanks for your advice.

    I checked Device Access, please see below. It looks ok to me.

    I asked my ISP about this a while ago, they are adamant they don't block port 8443.

    Config was downloaded after the hostname change.

    I tried the Tunnelblick client recommended by Sophos after not being able to get the Sophos client working on PC. I thought maybe Windows was blocking something. But again same result, no connection.

    It just seems to hang