<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Site to Site VPN Issues Between Sophos XGS 116</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/141446/site-to-site-vpn-issues-between-sophos-xgs-116</link><description>We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s. 
 
 - Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol? 
 Thanks Andr&amp;#233;</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Site to Site VPN Issues Between Sophos XGS 116</title><link>https://community.sophos.com/thread/526372?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 02:20:52 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b5b1057a-82a3-412a-8892-d7ef029224bc</guid><dc:creator>Raphael Alganes</dc:creator><description>&lt;p&gt;Hi Andre,&lt;/p&gt;
&lt;p&gt;Good day and thanks for reaching out to Sophos Community.&lt;/p&gt;
&lt;p&gt;In addition to Bharat J&amp;#39;s response above, which initially could guide you setting up IPsec site-to-site but to give insight to your questions above, It depends on the use case and your environment, security policy etc. -&lt;/p&gt;
&lt;p&gt;&lt;span&gt;-&amp;nbsp;Is it better to use a pre-shared key or an RSA key? These Authentication types has their own pros and cons that can be searched more but for the quick discussion of this use case - PSK max bits is 512, RSA key has more, both does not much require configuration overhead on a simple 2 Firewall site to site connectivity. But if this is multiple sites to be managed Digital certificate has it&amp;#39;s own advantage&lt;/span&gt;&lt;br /&gt;&lt;span&gt;-&amp;nbsp;In the firewall rules, should we put some IPS policy? Optimal security, you can use IPS.&lt;/span&gt;&lt;br /&gt;&lt;span&gt;-&amp;nbsp;In the VPN profile, do we use the IKEv2 protocol? If the other end supports IKEv2, it is better as it is the enhancement of v1&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Also, I may recommend you to reach out to your local Sales Engineer/Partner, I believe they can be of guidance with you on these type of engagements.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hope this helps. Many thanks for your time and patience and thank you for choosing Sophos.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Site to Site VPN Issues Between Sophos XGS 116</title><link>https://community.sophos.com/thread/526339?ContentTypeID=1</link><pubDate>Sat, 22 Jul 2023 19:49:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f3a82d0e-c07b-4afa-a1a6-c175d51bea7f</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;Hi &lt;span&gt;&lt;a href="/members/andre-soares"&gt;Andre Soares&lt;/a&gt;,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Follow this link&amp;nbsp;&lt;a id="" href="https://doc.sophos.com/nsg/sophos-firewall/18.5/help/en-us/webhelp/onlinehelp/AdministratorHelp/VPN/SiteToSiteVPN/VPNCreateRouteBasedVPN/index.html"&gt;https://doc.sophos.com/nsg/sophos-firewall/18.5/help/en-us/webhelp/onlinehelp/AdministratorHelp/VPN/SiteToSiteVPN/VPNCreateRouteBasedVPN/index.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>