Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to connect vpn from lan zone

Hi, 

I am working with a XG-310 with SFOS 17.5.10 MR-10

I have configured the remote access L2TP vpn and Sophos connect client vpn. It is working as expected when the vpn connection is established outside of the office environment via internet.

Now, when I am inside the office environment and try to establish a vpn connection from the internal lan zone, I am not able to do so.

The live log shows the appliance access is denied.

 

Although I have configured the firewall rule from lan to vpn without nat, it cannot work.



This thread was automatically locked due to age.
Parents
  • Hi  

    Is there any specific requirement to establish the VPN connection from LAN zone, VPN is meant for remote connectivity.

    LAN to VPN firewall rule will come into the picture when there are a VPN connection and traffic is initiated from LAN to sent via VPN tunnel, not used to connect VPN.

    Regards,

    Keyur
    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Hi Keyur,

    Thanks for the reply. Yes there is specific requirement to establish vpn from lan zone, we put in place some restrictions in the lan zone, only certain users with vpn accounts will be able to login and access according to the rules in place for the vpn users.

    I think you may suggest creating hosts for these users and implement further firewall rules, this is a way but it is not as good as having the user login via vpn because the host device may change.

    We used to have a utm firewall that does not need any special configurations in place for users to login vpn from lan zone.

    Can you let me know if this is a non-capability of the XG firewall? (Establish vpn from lan zone)

    I will find a work around if it is, instead of spending more time trying to look for configurations to make it work.

    Thanks.

  • Hi  

    Sorry for more questions but it would help me to assist you better, if the users are already in the LAN zone of the firewall, they can easily access the LAN resources as per the configuration, VPN is used when the users want to access resources from a remote location. If you want to restrict LAN resource access for VPN, you can configure SSL VPN and define separate policies as per the user requirement.

    Regards,

    Keyur
    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Hi Keyur,

    Certain lan resources are restricted. We would like only privileged users with vpn accounts to access these restricted lan resources. We have dhcp in the lan zone so we would like to track the access by means of vpn connections.

    We currently do not have ssl vpn setup due to users already setup l2tp connections inherited from the old utm firewall.

    Our use of vpn is slightly different to yours. In our case, vpn is used when the users want to access (selected) resources from a remote location (and local area connection).

    Perhaps you can answer directly to this question? The XG firewall cannot support l2tp and Sophos vpn connection established from the lan zone? Once you have given me a clear answer on this, we can discuss together what are the alternatives which are suitable for our use.

    Thanks.

Reply
  • Hi Keyur,

    Certain lan resources are restricted. We would like only privileged users with vpn accounts to access these restricted lan resources. We have dhcp in the lan zone so we would like to track the access by means of vpn connections.

    We currently do not have ssl vpn setup due to users already setup l2tp connections inherited from the old utm firewall.

    Our use of vpn is slightly different to yours. In our case, vpn is used when the users want to access (selected) resources from a remote location (and local area connection).

    Perhaps you can answer directly to this question? The XG firewall cannot support l2tp and Sophos vpn connection established from the lan zone? Once you have given me a clear answer on this, we can discuss together what are the alternatives which are suitable for our use.

    Thanks.

Children