Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Full tunnel site to site IPsec VPN bug

Hi All,

We have a question in Full tunnel site to site IPsec VPN.
When we create a local 192.168.183.50/32 to remote Any site to site IPsec VPN.

 

We found that XG's own routing will also be carried out through this VPN tunnel.

There is a similar discussion in the forum, link as below.

https://community.sophos.com/sophos-xg-firewall/f/discussions/127846/firewall-traffic-gets-routed-in-full-tunnel-ipsec-vpn?ReplySortBy=CreatedDate&ReplySortOrder=Ascending

I have tried 17.5.14 and 19.0.3, and both of them have the same bug.

Does anyone know which version of firmware this bug is resolved in?



This thread was automatically locked due to age.
Parents Reply
  • Hi  Thanks for sharing the detailed information, let me try to reproduce the issue in my LAB between XG to XG to confirm the results and I will update you based on my testing. 

    Additionally, a similar investigation is ongoing with the GES/Dev team for one such reported instance with ID NC-125618 - which is still under progress. I suggest logging a support case to validate it further on this one with the help of the support team. 

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

Children