We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s.
- Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol?
Thanks André…
I am using Unraid NAS on a remote site without public IP. It has support for Wireguard server. I assume there is also a wireguard client. Can this remote NAS connect to my Sophos XG appliance so I can remotely access the remote Unraid NAS? Is this called…
Hi,
Since a few days I see the same LOG entry on all XG Firewalls with active IPSEC VPN configuration. (I have checked more than 8 firewalls). The attempts come from the same IP 213.109.84.251 on all machines. Nslookup on this address returns the domain…
Anyone in the community has configured Sophos to Smoothwall site-to-site vpn? we have issues establishing the VPN connection between two sites
The Details for Phase 1 and Phase 2 are all matching
we created firewall rules on both ends
the status…
Hello,
I need help with tunnel configuration. For now I have working ipsec connection to remote 3rd party firewall and sd-wan route to route traffic coming from my network (172.19.19.0/24) to destination ip addresses through tunnel interface.
The…
Hi All,
I inherited a SITE to SITE configuration that I believe is misconfigured. I am in hopes that I can get help to understand the best way to do this. It doesn’t seem right. Maybe I’m just missing a Failover group on the first site.?
1st XG125…
I have created ipsec tunnel to enable branch office to access head office, tunnel on both offices are 'up' but xfrm gateways on both sides which i have used in sdwan routing are 'down'. but by using diagnostic tool i can ping both xfrm interfaces but…
Hi, we have an XG135 in the headoffice and an XG87 in the branch office.
in the headoffice we have two servers ( mail and something else ) that need to be reachable from the outside and we used the Server Accesss Assistant to create the correpsonding…
hi,
we have the problem that an IPSec connection between SG and XGS shows Terminated status several times a day and then the status changes directly back to established and the connection continues to work without problems.
What settings or logs should…
Hello,
We have the following scenario:
Two Sophos XG310 with active-passive high availability enabled. Since we configure high availability from time to time, the site-to-site ipsec VPN service just stops working, 80% of our tunnels are disconnected…
hi all,
we encountered some limitation with sophos fw, under SFOS 19.5 with IPSEC configuration.
There is no possibility to set null encryption under ipsec phase 2 part.
Is there a way to bypass this limitation ?
Hi,
I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side
Here's my config :
Sophos XG - SFOS 19.5.2 MR-2-Build624
Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
Hello,
I got a IPSEC VPN from my sophos xg to remote firewall.
Many subnet from my side are nated dynamiclaly with 172.30.10.0/24 to reach different subnet on the other side. Like (192.168.1.0/24 , 192.168.2.0/24 ...are nated with 172.30.10.0/24…
Hello Team!
In my environment, I have groups created in Active Directory to control remote access via VPN on the firewall.
Turns out this VPN group I created in AD, in the firewall's webadmin when looking up the user, is listed in the Other group…
We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script.
The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Episode #1
community.sophos.com/.../sophos-purposefully-designs-bugs-into-their-firewalls-episode-1---vpn-failover-and…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Our Background:
My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
We have a Sophos firewall xgs 2300 v19.00, the firewall is configured VPN to branches, machine at the branch office are failing to activate ESET endpoint.. at the head office we have a ESET server
Hi,
Encountering a weird error when trying to attempt using a server for DNS forwarding.
We have a few branch offices - each connecting to DC via IPSEC (Connection Type: Site-to-Site / IKEv2) - with the DNS Forwadering Host in the DC.
Now here's…
Hi,
we are using sophos xg firewall we need to create one tunnel between two site both side sophos xg firewall.
head office having all server and ad and dc server also. so all user are in branch office access server head office and all internet traffic…
I am able to ping My my gateway from HQ which is my XG Firewall LAN interface ,but i am unable to ping anything in the LAN ,from Branch Router to HQ Router i have a GRE Tunnel,What do i need so that i am able to access LAN resources in Branch
Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using:
Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
Hi,
Apologies for the question, I've returned to using Sophos XG after exploring pfsense further again. With XG Home my understanding is it doesn't leverage to the cypto extensions on CPUs like pfsense, so "potentially" VPN performance might not be…
Can anyone tell me how i can stop this from happening?
The IP address is from Ukraine and nothing to do with this connection or s2s so I am a bit worried its some sort of attempted hack on port 500.
Ive put a block (drop) on the IP incoming but thats…