Hi,
Is MAC binding feature introduced in v19.5. As we want to achieve MAC binding in IPsec remote access VPN so that only allow MAC addresses can connect to VPN. After searching, this is not achievable as XG doesn't recognize MAC pre-connection.
Regards,
Abdullah Siddiqui
Hello,
Thank you for contacting the Sophos Community.
MAC binding is supported in the Firewall; however, for Remote Access VPN, the Firewall can't bind remote access VPN users with MAC addresses because the Firewall won't see the Mac address of the device.
Regards,
Hi Emmanuel,
Thanks for sharing. we have already performed this, but this doesn't provide us the required results. Further, in live user tab users showing does not contain MAC addresses which might mean that IPsec is not learning MAC addresses?
Regards,
Abdullah
Hello,
As mentioned, MAC binding isn’t supported for Remote Acess IPsec. This is because the Firewall will never see the original MAC address of the computer attempting to connect.
Regards,
Acknowledged! I was replying to someone from your team who asked me to configure it by binding MAC address but he deleted his comment. Never mind, thanks for your clarification as wanted to share Sophos team verdict on this matter.