This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Device Access: SSL-VPN from VPN Zone greyed out - like from Site-2-Site

We're having the situation that we cannot allow SSL VPN Device Access to a central XG Firewall from locations connected by Site-2-Site IPSec tunnels.

That's because the remote locations are automatically assigned to VPN zone in XG.

And SFOS does not allow to enable SSL VPN for the VPN zone - it's disabled. I wonder why there is this limitation? What's the reason that there is the need to deny this?

The only way to enable this is by ACL Exceptions from "Any Zone" and I hate that.

Isn't there a better way to do that? Transparent and easy to manage?

You may ask why we're doing such things: that is because we're requesting users to connect once to SSL VPN from their office after they received a new computer or a new Sophos Connect Client installation with .pro file. So they can be sure, they have the configuration loaded in their SSL VPN client and that it's working.

SFOS 18.5. MR3

This thread was automatically locked due to age.
Parents Reply
  • you would tunnel a tunnel. So from this perspective, this will cause a lot of trouble. Maybe that is the reason it was disabled per default. You will run eventually into a lot of problems of MTU size problems 

    Perhaps that's why you cannot enable it. I guess some admins would configure and let it run that way.

    In our case we just need it to load SSL VPN Config with the CC .pro file once. Else we would need userportal open on WAN zone and let user do their first connect from a Guest WiFi or at home.

  • The Download feature within the .pro only requires User Portal to be reachable. The SSLVPN will not work afterwards. But the download will work.