Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos SSL VPN XGS116

Hii 

I have configure SSL VPN; this works well, and clients can connect.. The issue is that we can only access or connect to the devices or nodes that's it's gateway is the firewall IP, we other sophos GW but VPN client cannot access these until we change the gw to the one that has the ssll vpn. 



This thread was automatically locked due to age.
Parents Reply Children
  • Hello Shoug, 

    Thanks for sharing these details. From what I understand, Only those whose Default gateway on Local subnet (172.16.100.0/21) is Sophos Firewall are able to establish connection? 

    -What is the Firewall IP (Default Gateway), What are the other DG IP on the local subnet? 

    The reason behind why they can connect back when SF is their DG is, SF knows the route back to SSL VPN network when you set another DG/router that does not know or do not have specific policy to connect to the SSL VPN network, traffic will fail. If you opt to go along the path where SF is not the DG, the router/DG must have a route to 10.81.234.0/24 network --> through the Sophos Firewall then SF --> SSL VPN Network. 

    If you do not have any complex reason or setup, I would suggest changing the LAN network DG to Sophos Firewall IP. 

    Kindly let me if my understanding on your setup is correct. Hope this helps and thank you for choosing Sophos. 

    Regards,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Raphael,

    Thanks for the reply. The other DGs that we have are also Sphos FW.. The thing here is that there are a lost of devices that we should back and change to the current SSLVPN FW as their DG,, It will be better if I can solve this to connect even if the device DG is not like thw SF that has the SSL VPN. 

    The current SF that has the VPN 100.244 we have other SF with differing IPs (100.245, 100.240, and Sophos UTM 102).208