Disclaimer: Please contact Sophos Professional Services if you require assistance with your specific environment.
This article describes the steps on how to configure BGP routing over a Route-Based VPN (RBVPN) tunnel using the Sophos XG Firewall with SFOS version 18. This procedure will work between two Sophos XG Firewall devices as well as with a third-party network device as long as it supports RBVPN.
Note: This article does not provide in-depth information regarding BGP, RBVPN, or firewall technologies.
Applies to the following Sophos products and versionsSophos XG Firewall version 18
Establish BGP routing via RBVPN tunnel between the Head Office (HO) and the Branch Office (BO).
The configurations provided here are just an example. You can configure according to your organization's networks and requirements.
Configure the maximum path
You need a static routing point the firewall to the next hop.
Hello to all,
I followed your configuration step by step but still does not see the session go up, it remains in ACTIVE, should I open some regular detail to let the neighboors communicate?
2 Tunnel are same UP but cannot establish the peering.
from one sophos:
router bgp 64743 bgp router-id public_IP network 10.0.4.0/24 neighbor 220.127.116.11 remote-as 64742 maximum-paths 2
router bgp 64742 bgp router-id Public_IP network 192.168.46.0/24 neighbor 18.104.22.168 remote-as 64743 maximum-paths 2
Thank you for contacting the Sophos Community.
What does the /log/bgpd.log shows?
Do you happen to have any static route pointing to the Public IP of the router(s)?
What is the output of bgp> enablebgp# show ip bgp
Thanks for the reply, no static route.This are my logs:XG125_XN02_SFOS 18.5.1 MR-1-Build326# tail -f /log/bgpd.log 2021/10/14 17:40:37 BGP: 22.214.171.124 [Event] Connect start to 126.96.36.199 fd 102021/10/14 17:40:37 BGP: 188.8.131.52 [Event] Connect failed (Operation now in progress)2021/10/14 17:40:39 BGP: Import timer expired.2021/10/14 17:40:54 BGP: Import timer expired.2021/10/14 17:41:09 BGP: Import timer expired.2021/10/14 17:41:18 BGP: Performing BGP general scanning2021/10/14 17:41:18 BGP: scanning IPv4 Unicast routing tables2021/10/14 17:41:24 BGP: Import timer expired.2021/10/15 08:58:18 BGP: Vty connection from 127.0.0.12021/10/15 08:58:18 BGP: ####Inside vty_create ()bgp# show ip bgpBGP table version is 0, local router ID is 184.108.40.206Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, R RemovedOrigin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path*> 220.127.116.11/24 0.0.0.0 0 32768 i*> 192.168.46.0 0.0.0.0 0 32768 iTotal number of prefixes 2
thanks I look forward to your feedback
Hello, can i have your feedback? grazie