This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issues with VPN Site to Site from Sophos Firewall to Cisco ASA

Hello,

Perform a Site to Site VPN configuration Sophos FW to Cisco ASA, when I select the KEY Exchange in IKE1 the VPN connects correctly, the problem is when I select IKE2 since the connection is not made.

Could you please help me solve this problem since the CISCO ASA is from a provider and they ask me for IKE2 for the VPN connection.

Annex screens of the configurations and the logs generated in the sophos and in the cisco ASA.

This is the only thing that the provider (CISCO ASA) sees in the logs.

Grateful for any help you can give me.

Atte.
Ronald



This thread was automatically locked due to age.
Parents Reply Children
  • If you have private IP on Cisco and Sophos side under WAN/untrust Zone, make sure you have allowed ESP protocol and port 500 on udp on your upstream routers as well as suggested by  Vivek Jagad

    Phase I and Phase II Policy should match at both the end

    Thanks and Regards

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.