Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing system generated traffic via IPSEC with failover

Hi all

I have a site where the XGS2100 is currently set to authenticate against the local AD Domain Controller. The DC is planned to move off-site and so the XGS will need to authenticate to the DC via IPSEC - the DC will be hosted behind an OpnSense firewall in the new location. I have followed the guide here (Route system-generated authentication queries through an IPsec tunnel - Sophos Firewall) and can successfully reach the DC. The catch is that the XGS has 2 internet connections with IPSEC set up with a Failover group, and the XGS must be able to reach the DC via either of the IPSEC tunnels. How can I achieve the desired outcome here?



This thread was automatically locked due to age.
Parents Reply
  • Thanks for your update. I am more clear now about the requirement 

    Please correct me if I am wrong here 

    IPSec VPN between Sophos XGS2100 and OpnSense firewall is working with Route base IPSec VPN and SYSTEM-GENERATED D traffic through the IPSEC tunnel, where your DC is connected to OpnSense firewall and you can authentication users with DC under Sophos XGS2100.

    Now above configuration is done with ISP1 for IPSec site to site and you want to connect IPSec with another ISP 2, so that if ISP1 fails, IPSec route base VPN should work with ISP 2, if yes below would be the configuration link 

    https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/index.html?contextId=ConfigureRBVPNISPs 

    Please post the in case above configuration steps if already done and not working.

    Regards

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data