Sophos Firewall v18 AWS site-to-site VPN connected but no traffic PING SSH

Well, I have followed this step-by-step, exactly:

https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/125560/sophos-xg-firewall-v18-to-aws-vpn-gateway-ipsec-connection

....and while the VPN shows "UP" in both AWS and my Sophos VPN section, I cannot PING or SSH to my test EC2 instance. In the bottom screenshot you'll see I have PING and SSH allowed from anywhere (0.0.0.0/0). I've been at it for hours, first because I mistakenly followed the v17. Even with the v17 how-to, my VPN said it was up in AWS and Sophos VPN section. Then I found v18 and thought for sure I would have success. No such luck.

At one point I got stuck at the part where I couldn't find my "xfrm" interface until I realize that little vertical blue line meant I could expand my WAN interface, thanks to THIS ARTICLE. Again, I thought for sure I would have success. No such luck again, and now I'm at a loss. 

The only difference I've noticed between my setup and the setup in the link above, is in Step 9 and Step 10, I have "xfrm1" not "xfrm2".

Anyone know where I should start with troubleshooting?



Edited TAGs
[edited by: emmosophos at 11:48 PM (GMT -7) on 26 Aug 2021]

Top Replies

Parents Reply Children
  • No. I've only been deleting/recreating the VPN stuff, and attaching it to my existing test VPC (on a 10.10.0.0/16) network, which then has a 10.10.1.0/24 subnet in it with my test EC2 instance at 10.10.1.93. I'm guessing one shouldn't have to completely delete/recreate an EC2 instance... instead, just make sure your newly created Virtual Private Gateway is attached to the existing test VPC and the correct routing and firewall rules are in place. In any case, I just created a new EC2 instance (10.10.1.13) and cannot PING or SSH to that either. My VPC and Security Group was created using the "Set the AWS side" section of the Sophos v17 AWS VPN tutorial -- because the Sophos v18 AWS VPN tutorial completely leaves all of the VPC creation stuff out.