Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Azure Pfsense 23.09.1 site to site ipsec to on prim sophos SFVH (SFOS 20.0.0 GA-Build222)

    For a few days now I have been attempting to get a ipsec site to site between these two firewalls and even have the pro customer support pfsense involved. All there suggestions have been unsuccessful in getting the two to talk to each other. all guides…
  • VLAN in a IPsec Tunnel randomly stop communicating.

    Hello I recently upgraded my Sophos XG 2300 to SFOS v20 which is in Head Office, where I am running site to site vpn: IPsec tunnels to 6 branch offices and IPsec Profile is set to Head Office, policy based for all IPsec Tunnels on Head Office firewall…
  • Site-to-Site VPN

    Hi, I have a constellation with a site-to-site VPN between a Sophos XGS116 and a Sonicwall TZ400 at a customer's. The connection between the two devices keeps breaking down. On the Sonicwall you can also see that the VPN tunnel has been disconnected,…
  • Can’t route self-generated packets

    Hello, I work on 2 Sophos XG on 2 different sites. They communicate with each other using a Site-to-Site IPSec VPN. Site A : Sophos-XGS 33100 (SFOS 19.5.3) Site B : Sophos-XG 330 (SFOS 19.5.3) 3 subnets of Sophos A are configured to be able…
  • on Sophos Firewall, if I update and regenerate the default CA, what are the implications?

    On Sophos Firewall, if I update and regenerate the default CA, what are the implications? I have a firewall that is setup, the default CA hasn't been customised so far. I need to setup a S2S IPsec VPN with certificates and wanted to customise this before…
  • Firewall Policy with Limited Access no Working

    Hi, I have two WAN Links. Firewall rules and sd-wan routes are created. If I add a new firewall policy to allow internet for a server that is not included in the default policy, it does not work. I created a new nat policy and sd-wan rule, but it did…
  • Unable to connect Digibox/Bintec Router to Sophos XG via IPsec

    Hello, I'm unable to connect a Telekom Digibox (branded Bintec Router) to a Sophos XG via IPsec VPN. charon.log of the Sophos Firewall: 2024-02-16 12:26:17Z 28[NET] <9> received packet: from <branch ip>[500] to <head ip>[500] (512 bytes) 2024-02…
  • Unable to establish the site to site communication between sophos firewall to Microtik router

    We set a local ip to our branch office 13.1 to the microtik switch and configured the IP sec in sophos firewall and established the connection and connection also up. We created the policies in microtik and added the IP address. Then established the connection…
  • SOPHOS 2 BRANCH CONNECTION

    Hello I have two branches, both with Sophos firewalls. I have run fibre between these branches; how should I connect them so that they share resources? I have configured a site-to Site VPN, but what if one side loses internet? I need a backup.
  • Sophos Site to Site IPSEC Conection with Selectet Clients

    Hello dear Sophos Forum, I have set up a Site-to-Site VPN connection between a NAS and 2 ESXi servers with a Sophos XGS. Setting up the connection was no problem, but I still can't reach the ESXi servers from the NAS, even though every port is allowed…
  • Vendor router/ipsec tunnel on /29 routed subnet behind /30 sophos xg. Tunnel disconnecting.

    Summary: AT&T provides us a /30 for our equipment and a /29 routed subnet. We are currently using several of these addresses as Alias NAT'd for hosted services. We have a vendor who wants to establish a VPN tunnel to their remote site via a cisco 4300…
  • POLICY BASED IPSEC VPN with Source NAT (MASQ)

    I'm migrating from a UTM to an XG so i'm trying to replicate a config that already existed. I have the IPSEC VPN setup and the tunnel comes up. The VPN selector on my side only has a /30 I need to have the rest of the organisation talk through this VPN…
  • Using public IPs in different locations with IPSEC

    Good morning. I don't know if someone can help me as I have been trying various configurations and conducting tests without any success, and I'm not sure if the XG allows what I need. I have 2 offices: Office A has a public IP addressing (e.g.,…
  • Site-to-Site VPN FritzBox -> Sophos XG

    I have established a VPN Tunnel between * Sophos XG (Head Office) * FritzBox (Branch Office) I can access Head Office Resources from Brach Office. But I cannot access the internet from Branch Office. I have created a Firewall Rule to allow Branch…
  • RDP freezes for 5-10 seconds

    So we have a pretty new XGS 2300 and we have some cases where we connect to our customers servers over an Ipsec Site-to-Site tunnel with RDP. the tunnel is stable but sometimes the remote desktop session freezes for a short time. I looked into the…
  • Connected to Sophos VPN has Internet but can't ping anything it always show ("Request Time out")

    there is internet before and after connecting vpn but every time I ping anything the result is always "Request time out". however after conecting to vpn the internet is slowing and cant ping servers Help me to fix this.
  • malformed payload in packet. Probable authentication failure (mismatch of preshared secrets?)

    I am trying to configure ipsec Site-to-site VPN between the Head and branch offices. The Head office is a Sophos UTM SG 210 configured as the responder (Repond-Only), and the branch Firewall is a Sophos XGS configured as the initiator. The Head office…
  • unable to Allow Internet access from head office to branch office through mols VPN

    Good day we are using sophos firewall xgs 87 I have a problem. I want to allow the internet to go to all branch offices through the XG firewall at the head office. via ,mols vpn The other branch office has a Sophos firewall, Currently, I have…
  • IPSec site-to-site Reauthentication

    How do I enable reauthentication for site-to-site IPSec connections ? Sophos XGS3100, SFOS 19.5.3 MR-3-Build652
  • VPN IPsec site to site between Sophos and Fortigate

    Hello, I have to create several site-to-site IPsec between Fortigate Firewall and our Head Office Sophos Firewall. All connections must go to the same subnet in our Head Office. I've configured the Sophos as "Respond Only", the subnets are configured…
  • VPN Site to Site - Questions about encryption

    Hello everyone, To configure a site-to-site VPN between two XGS 116, is it better to configure encryption as IKEV2 on both firewalls or DefautHeadOffice for the headquarters and DafautBranchOffice for the branch? Thanks André Soares
  • Only one way traffic ipsec site to site vpn

    I have a new Sophos XGS116 I have just installed replacing a Cisco ASA5506. (Site B) I setup the s2s with the same profile and settings (not subnet or public IP) as I use on another XGS116 (Site C) for the same customer. Both these 116s have a site…
  • Multiple IPSEC Tunnels with Combination of RSA and Preshared Keys.

    Been using 1 same preshared keys for over 10 sites that backhaul back to our HQ till now. However eversince v18 onwards, it's getting more and more unstable. After restarting our HQ Firewall, at least 3-4 sites tunnels wouldn't up. Ticked the create firewall…
  • Can't access remote server via IPSec s2s after migration (xg135w to xgs136)

    Hi, We have an IPSec s2s connection, and there is a remote subnet 10.0.0.0/255.255.255.0. Migration was done with configuration export/import and it seemed almost everything migrated successfully (only some firewall rules involvind ad users where…
  • XFRM Interface Diagnostic

    2 XGS connected via ISP PTP fiber as primary. Each XGS has a second ISP which will be used for a IPSEC tunnel in case the primary link fails. Currently OSPF is in use. I have a IPSec VPN between 2 XGS using a tunnel. Both XFRM interfaces are 192…