Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • IPSEC VPN Client connected but no access to internal resources

    Hey guys, no change and I don't unterstand where is the problem. I have a Macbook. The internal Client ist connected but no access or ping to the internal resources. Any idea
  • IKEv2

    When will IKEv2 for Remote Access VPN be available?
  • Sophos Connect ipsec VPN Geo restriction

    In SFOS 19.x or 20.x is it possible to restrict Sophos Connect (remote access) ipsec VPN clients by country without putting a 2nd XG firewall in front of the XG serving the VPN? Example: permit client vpn connections only from Canada.
  • IPsec Remote Access VPN - Change Client information name (field greyed out)

    Hello Sophos Community, I'm rolling out Sophos Connect Client and IPsec provisioning file via group policies for a customer right now, everythings working fine except for one thing. When the vpn provisioning file is imported to sophos connect client…
  • IPSec Remote Access VPN not passing traffic XGv19

    We are fairly certain the setup is correct and the FW rules are in place, but remote access user cannot see internal resources on the LAN (other than the SOPHOS FW) when connected. After SOPHOS Connects successfully establishes the tunnel, the user can…
  • VPN: Can't Access Windows Share

    We have an XG 135 running SFOS 19.0.2 MR-2-Build472. Today we are unable to access a Windows share on a particular server over VPN (either IPsec or SSL remote access). We can access the share from the internal network and shares on other PCs are still…
  • Sophos XGS v19.5 IPsec Remote Access fallback - 2 WAN IPs

    Hi, we are using the IPsec Remote Access as our home office solution. We have 2 ISP-connections connected to 2 seperate inferfaces on our Sophos XGS 3100 . Once i configured the IPsec profile and policy I stuttered that there is no option to select…
  • IPsec remote access and DNS host entries?

    Hello What are correct DNS settings for IPsec remote access client so it would use DNS host entries from firewall?
  • VPN IPsec Remote Access - Apipa Gateway on End Devices

    Hello Everyone, I am enabling IPsec remote access VPN on my firewall XG, the problem is that every time when the clients establish the VPN connection, my clients are getting an Apipa IP address as a gateway and the traffic toward those two IP (172.1…
  • VPN Setup

    Hello community. I'm pretty green with setting up VPN's so I have been studying like mad over the last few days every Sophos article and video I could find to try and do this myself but I have hit a brick wall. I need to connect a remote workstation to…
  • Improve IPsec remote access performance

    Hello Community, I'm in the process of switching my companies work from home VPN solution over to use our new Sophos XGS3100 Firewall. Currently we prefer to use the IPsec remote access service, as it is easy to deploy via the general .scx file and…
  • IPsec Remote VPN multiple Gateways in v19.5

    Hi, We have configured IPsec remote access VPN and wants to achieve two profiles for both primary and secondary ISP. We have come to know that it's not possible in IPsec remote VPN currently. But I have seen that we can have multiple Gateways defined…
  • User MAC binding for IPsec Remote Access VPN in v19.5

    Hi, Is MAC binding feature introduced in v19.5. As we want to achieve MAC binding in IPsec remote access VPN so that only allow MAC addresses can connect to VPN. After searching, this is not achievable as XG doesn't recognize MAC pre-connection. …
  • Enforce XG local users to change Password connecting through IPSec

    Hi, Is there an option to enforce local users created on Sophos XG2100 firewall to change passwords when they first login with their provided username and password on IPsec Remote access VPN Connection. Password change option is available in User…
  • Sophos XG V 19.5 IPSEC IKEv2 Remote Access VPN

    Hi Guys, is IKEv2 finally included in v 19.5 for Remote Access VPN? Thanks a lot, Dustin
  • Invalid Pase 2 ID Prosal. One user

    Everyone seems to be able to connect to the VPN, but me. I get this fault. We are using only one profile for IPSEC, although there are a few profiles in the system. I see support for if there are multiple profiles in use, but I do not see anything for…
  • IPSec Remote VPN no internet access

    Hi, I am having trouble getting my IPSec connection to work. I have managed to set up the VPN so it can connect, but the remote device is not able to connect to the LAN or WAN. I am testing it out on Sophos connect client, but my goal is to put the…
  • XGS 136: Connection issues from VPN to LAN when (unsubscribed) Web Filtering is set to 'None' in firewall rule

    Hi there, im struggling with a really strange issue. Maybe im also not aware how this works exactly and only need an meaningful explanation. Ive nothing so far in the KB neither on other web sites. Situation: - Remote Access VPN Ipsec configured…
  • Remote access VPN IPsec - Gateway/Address in Provisioning file

    Hello, I did take a look at the IPSec VPN for remote access in Sophos Firewall OS v19 and there is a value in the exported Provisioning file that i can't understand where the NGFW gets the value from. The Value is " gateway" or "address" depending…
  • Access Client over Remote Access (Client-to-Site) IPsec VPN

    Hi to the community, I have been searching for a while but did not find a solution, so hopefully somebody here can help me out. The following is, what I have: A client connects to the XG Gateway via Remote Access aka Client-to-Site. This client runs…
  • XGS-2100 IPSec Remote Access VPN Override Hostname

    Hello, I have a XGS-2100 and I am using IPSec for remote access. I am using Sophos Connect to connect PCs in via IPSec and would like to use the IPSec profile for iOS imported from the User Portal. My problem is, my XGS-2100 sits behind another…
  • Open VPN cant connect to Sophos XG

    Hello, from one day to another I cant connect to XQ (latest Firmware). Opebn VPN sayes (I wil post only RED sections here): Fri Sep 2 15:43:48 2022 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption…
  • Features for IPsec Remote Access

    Hello guys. I recently found out that the ideas portal is over and now it's here and also with the partner. I see a lot of new features from Sophos with each release, I love all the new features. A novelty that I hope is the possibility of using…
  • using Ubuntu 20.04 Jammy Jellyfish that use OpenSSL 3 can not connect to VPN using OpenVPN

    As soon as I upgrade my laptop to Ubuntu 22.04 that use OpenSSL 3 as default I can not connect to my workplace VPN. I try follow this suggestion https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1960268/comments/32 but it does not work. My workplace…
  • MTU for IPSec (Remote Access)

    Hi, Is there a way to set the MTU for the IPSec Remote Access VPN on an XGS2300 v19? I'd like to se if tweaking it improves performance for my remote users. Thanks, Jeff