Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Remote SSL VPN to IPSEC Site2Site VPNs

    Have setup SSL Remote VPN Connects fine and is able to access the LAN of the XG What i want to achieve is to be able to access IPSEC VPNs to other remote LANs via the XG. I have tried setting the VPN settings to use as default gateway and adding…
  • Sophos XG redirecting ping

    Hi. I have a problem with connectivity between two subnets on my sophos XG. The Sophos XG is my router and firewall and have 2 interfaces, one for wan and one for LAN. The LAN interface has 3 alias with 3 subnets, lets say 10.1.1.0/24, 10.1.2.0/24 and…
  • Windows update on secondary / backup link

    We have 2 x WAN links, one as a primary the second as a backup. we have found windows update killing our primary link of late so would like to send all windows update based traffic on the secondary/backup link. We are running a Sophos XG 16.05.8 MR…
  • Force specific websites through VPN tunnel?

    We utilize Azure for a number of things, one of which is housing certain databases and applications. Folks who work remotely and use the VPN to access our internal resources are not able to access these Azure resources because of IP filters we have in…
  • RED 15 with windows DHCP

    We are testing a RED 15 for a new branch office, here is what I would need. Main office: XG210 configured and running no issues here Branch office: (will have) 4 users 4 VOIP shoretel phone that have to connect to server at main office 4 desktops…
  • PPTP VPN cant passthrough behind mikrotik (transparant mode)

    Hi All, i wanna ask about VPN PPTP behind mikrotik not reach the destination (transparant mode), can someone give another information? actually the user can get IP VPN from mikrotik but they cant ping the server (destination) i already read about…
  • XG Active Passive HA Cluster Not Working

    I have two XG210's that I am attempting to configure in Active/Passive HA. I followed the instructions here: https://community.sophos.com/kb/en-us/123174 The firmware on both is 17.03 M3 I configure all the settings and it syncs successfully, however…
  • Accessing Local subnet over Remote SSL VPN Range network

    Created SSL VPN by following the KB122769 with the following settings: IP Host - Local subnet 192.168.3.0 IP Host - VPN Range 10.10.10.1 to .25 Under SSL VPN (Remote Access) I have Identity of Remote SSL Group and under Tunnel Access I have added…
  • RED15w does not receive WLAN config from XG (SFOS 17.0.3 MR-3)

    Hi all Just a perhaps simple question: New XG installation with 7 branches (6 Red15w and 1 Red50), all RED's work in standard / split mode and are in the LAN zone. The connection and routing between the branches works fine. The WLAN configuration in…
  • Is that possible to let a interface with 2 IP addresses?

    I am going to let a SOPHOS XG310 Lan interface to own two Lan Ip addresses as Client Gateway. Is that possible? The reason for my case is that my client currently is in an asymmetric routing problem which some hosts' gateway are to Sonicwall (192.168…
  • How do we route internet traffic from one IPSEC Tunnel to another IPSEC tunnel?

    Hey team - we want to route all internet traffic from one IPSEC tunnel (AWS:172.31.254.0/24) to another IPSEC tunnel (NIMBLHQ:172.31.149.0/24). Right now - all clients/servers on AWS:172.31.254.0/24 have no internet access. I can see the packets (shown…
  • Doubt with multiple VLANs on one port.

    Hi all, I'm a little bit confused with the VLAN configuration on XG. I'm running a XG310 with SFOS 16.05.8 MR-8. We have 4 VLANs: - VLAN 10: 192.168.10.0/24 - VLAN 20: 192.168.20.0/24 - VLAN 30: 192.168.30.0/24 - VLAN 50: 192.168.0.0/24…
  • why the wan port is always red

    I changed the cable. I changed the ethernet port. I changed the ethernet card. but always red.
  • How to set up two XG firewall ports to serve two independent LANs from one WAN?

    I am graduating from an ASG120 running UTM 9.5, which is end of life, to an XG 125 and have no experience with XG configuration. Two organizations in the same building share the WAN connection but want independent LANs. Each LAN will have its own DHCP…
  • Sophos Bridge Interface and Segregating traffic inside the switch using VLAN's

    Hello All, I hope u will be able to help me. I'm using bridge interface which gives me nice one subnet segregation. Everything works fine only if every interface Port1, Port3,... inside bridge have separate switches for each port. But this is…
  • How do you all blacklist IPs? I have 50K+

    Currently have blacklisted 50,000+ IP address in my Sophos XG210. I am running 16.05.XX. I started this in March and was blacklisting approx. 15K a month until August when I got busy. I am about to add 30+ more IP address and I want to get the opinion…
  • Sophos xg with two L2L Wan connections

    Hi, In one branch office we have one L2L connection working normaly your rounting network 172.18.0.0/16 (branch) to 172.16.0.0 (head office), in branch office the XG have port1 Lan 172.18.0.10/16 and port2 wan 172.16.0.14 ( because this link is L2L…
  • Sophos Azure XG can't route to Azure VM

    I have networking condition in Azure and believe I could be close based on what I've been reading. As it stands, I can ping/access the Sophos Azure XG from the Azure VM but not the reverse. Meaning I cannot ping the Azure VM from the XG. Packet cap shows…
  • WAN Gateway IP on a different Subnet

    Multiple VPS and online server providers these days provide you with a gateway IP that is on a different subnet than the WAN IP. On pfSense, Forefront TMG and Untangle firewalls, I can add the gateway IP even when it's on a different Subnet, but on Sophos…
  • setup 2nd lan on home network using VMware

    I have got the install completed and all is fine, running a VM under VMware workstation. I have port 1 setup as LAN on my virtual network. And port 2 setup as WAN (bridged mode), gets dhcp from my internet router. Everything works fine on the VM side…
  • RED 50 Set up Standard/Unified

    Good day, Please assist, I have set up a RED 50 in Standard/Unified to an XG 230 Created a Zone for RED and applied the RED device to the Zone Created Firewall Rules for RED to LAN, LAN to RED and RED to WAN On a device connected behind the…
  • SOPHOS XG - SSL VPN no access across IPSEC tunnel

    Have 2 sites connected with an IPSEC tunnel 192.168.1.0 - head office (SSL VPN 10.81.234.0) 10.1.10.0 - branch office (SSL VPN 10.81.235.0) when a user connects via ssl vpn they can't communication to the other site. What do i have to add in order…
  • Can't ping secondary WAN link from Internet.

    Hi all, I have 2 WAN links, both are from different ISP. One of them (GW-principal) it's working flawlessly, the sencond one (GW-secundario) was the backup link for the GW-principal. We decide to change the link state from Backup to Active so we…
  • Allow ip range in one VLAN to use gateway in other VLAN

    Hello I just (partially) installed an XG105. Most things work correctly but I'm having trouble getting a policy routing rule to work. This is the situation/problem VLAN10 (10.10.0.0 / 255.255.0.0) VLAN40 (10.40.0.0 / 255.255.225.224) range determined…
  • Setup clientVPN from XG to VPN Server

    Hi, I Need to setup a OpenVPN client connection from the XG to the VPN server. Is this possible? And if so, how do I establish this? Greets, Jeffrey