Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • IPsec Remote Access not Receiving traffic

    I need some assistance please. Also i am new here, in the community. My ipsec remote access sends traffic but does not receive. See the screenshots of my configuration:
  • IPsec Remote Access from iOS using certificates not asking for password

    Hi guys I can't see the wood for the trees -- so please forgive me this (probably stupid) question: When using PSK for IPsec without certificates, everything is working properly. It asks for password (or I save my password) click Connect and it works…
  • Sophos Firewall - Remote access VPN - IPsec - download IPsec VPN profile for iOS fails

    Hi folks, I did setup a remote access IPsec profile with a uthentication type digital certificate. The local certificate was created with a CSR by the firewall with help of OpenSSL under Linux and the remote certificate as described in docs.sophos…
  • No response from gateway

    Sophos XG XGS116 (SFOS 20.0.2 MR-2-Build378) has problems with ipsec vpn. The Sophos Connect client shows "No response from gateway [Adress]" So we took a look on the firewall at "Administration" and "Device Access". Here we have IPSec selected. …
  • Remote IPSEC VPN doesn't work after configure SD-WAN route

    Hi, Good day! I am looking for guidance regarding my network configuration involving two ISPs connected to my firewall. One set as active and the other as a backup. This setup has enabled us to utilize Remote IPsec VPN effectively. I am currently…
  • Disconnect after 30600 Seconds, but cannot find this value

    We use Remote acces VPN with our XGS2100 (SFOS 20.0.2 MR-2-Build378) and Sophos Connect client. All VPN Connections disconnect after 30600 seconds oder 8,5 hours. In the Profile we do not have any lifetime or margin set to this value. Phase 1 Key…
  • Probleme mit Sophos XGS IPsec-VPN (iPadOS) und Deutsche Telekom

    Sehr geehrte Community, ich habe ein Problem mit iPadOS und der IPsec-VPN-Verbindung in Zusammenhang mit der Telekom. Beim Versuch, einen VPN-Tunnel von meinem iPad aufzubauen, gelingt dies nur unregelmäßig. Lediglich (geschätzt) 2 von 10 Verbindungsversuchen…
  • Remote IPSEC VPN Disconnections

    Hello Sophos Community, Is there any documentation or procedure to troubleshoot end user disconnection from our remote access IPsec VPN? I have been looking on how to look at the firewall logs but I couldn't finds anything usefull.
  • Remote Access IPSEC - tunnel connects but unable to access any devices

    I have configured Remote Access VPN - IPSEC and I am able to establish a connection via the Sophos Connect app. However, I am unable to talk to any LAN devices connected to the Sophos XG 125W. Here are my configuration settings: 1. Remote Client…
  • Sophos XGS time based VPN

    Hallo, how is it possible to control the IPSEC Remote VPN Access time-based on the XGS, so that the users can only establish a connection at certain times? Thank You!
  • Can't access servers after expanding network over IPsec

    Hi Everyone, I can't figure out why can't I access any of my servers over VPN (IP Sec) after expanding my network from /24 to /22 I'm running SFOS 20.0.1 MR-1-Build342 Here's my setup: Before network expansion Network, LAN Zone, IPv4/netmask…
  • DNS resolution over VPN issue when LLMNR is disabled - Sophos Conect 2.3

    I have the same problem as described in the following post: RE: LLMNR disabled - DNS resolution no longer works over VPN I have now updated to 20v1 MR1 and installed the current Connect Client. Unfortunately, the error is still not fixed with Sophos…
  • Sophos Connect - Sophos TAP Adapter unidentified network

    Every time I wanted to connect to a VPN via Sophos connect the connection was established for the first time but then the Sophos TAP Adapter card displayed unidentified network, The temporary solution is to deactivate/activate the card to be able to connect…
  • Unable to access remote access VPN L2TP Client from main office

    Hi I am trying to ping/RDP L2TP client from Main office but unable to access but through L2TP client I can access my office network. Thank you Policy tester Rules and policies NAT Rule
  • Sophos Connect Setup Wizard ended prematurely

    Hello I have Paralels Windows machine on MAC and I cannot install Sophos Connect. The message is Sophos Connect Setup Wizard ended prematurely MAC OS SONOMA ver. 14.3 Paralels ver. 19.3.0(54924) Windows11 ver 22H2 Sophos Connect ver. 2.3.0 …
  • IPSec VPN access

    I'm using the Home Firewall 20.0. I configured IPSec VPN using the Sophos instructional video. I used the default profile. I'm on the road, and trying to connect to devices on my home LAN, via the VPN. Let's call the LAN subnet X.X.X.0/24. The Sophos…
  • LLMNR disabled

    Hello, regarding to this post: LLMNR disabled - DNS resolution no longer works over VPN when will version 2.3 of sophos connect be published? kind regards
  • IPsec Remote Access VPN - Force specific traffic through VPN

    I reviewed this : Force specific websites through VPN tunnel? This works for SSL VPN. However adding a host IP under IPsec Remote Access does nothing. Also cannot add an FQDN host under IPsec Remote Access under v20. Is there any way to get this…
  • How to find out IP-Adresses of incoming ipsec vpns at sophos xgs firewall

    We have a sophos xgs with several ipsecn vpns site to site running. the Sophos XGS is responding to some VPNs that are without fixed public ipv4 adresses. One VPN incoming has no fixed static ip adress, but i need to enter that ip-adress at xgs to…
  • How to modify target Host for IPsec remote access

    With Sophos Connect Admin I can modify Target host definition for IPSec remote access connection. With XG I can do same already on XG for SSL VPN (Override hostname). However, I cannot override hostname for IPSec remote access configuration via Web-console…
  • Change AD Domain name for IPSec

    Hi Our staff currently VPN using the Sophos Connect client over IPSec with AD authentication. We are having a rebrand so will be changing our external domain name. But we will be keeping our old one. How do I confirgure AD and Sophos to use the…
  • Sophos Connect(IPSec): VPN User keep logging out

    Hello, yesterday we set up MFA for IPSec Remote Access. We are using the local MFA. Now we having Problems with some Users, because after some time there are automatically logging out of the vpn (Sophos Connect). See Logs: Before the MFA. We used…
  • IPsec client disconnection problem , at 60'minutes firewall XGS116 (SFOS 20.0.0 GA-Build222)

    Hello , on upgraded system SFOS 20.0.0 GA-Build222), we encounter problems with VPN Client IPsec disconnection after 60 minutes, the system does not take into account the Dislabe Disconnect when tunnel is idle. can you help me solve problem , i have…
  • Allow Guest Wirless to VPN for testing

    I would like to allow access to our IPSec VPN from our guest Wi-Fi for testing purposes. I have created a simple rule that allows internet access. Unfortunately, I always get an error when setting up the VPN connection. Anyone know a solution…
  • Remote access VPN IPsec - Gateway/Address in SCX/Provisioning file

    Currently when you export the SCX file (or use a provisioning/pro file to automatically update the VPN configuration in the Sophos Connect client) the file's "gateway" parameter has the WAN IP of the Sophos XG firewall. Our firewall is currently behind…