Reflexion will be End-of-life on March 31,2023. See Sophos Reflexion EoL FAQs to learn more.
Disclaimer: Please contact Sophos Professional Services if you require assistance with your specific environment.
1. Sophos Firewall v18 firmware
2. Your OnPrem Sophos Firewall and the following information:
3. Your Microsoft Azure vNet and the following information:
The local network gateway typically refers to your on-premises location. You'll need the public IP address of your On-Prem Sophos Firewall and your On-Prem Private IP address spaces. Please note that this configuration assumes that the public IP address is directly configured on the On-Prem Sophos Firewall. Your configuration will be slightly different if your On-Prem Sophos Firewall sits behind a NAT device.
The local network gateway typically refers to your on-premises location. You'll need the public IP address of your On-Prem Sophos Firewall and your On-Prem Private IP address spaces.
Please note that this configuration assumes that the public IP address is directly configured on the On-Prem Sophos Firewall. Your configuration will be slightly different if your On-Prem Sophos Firewall sits behind a NAT device.
In the "Create local network gateway" blade, configure the following and then click on "Create":
The VPN gateway will be deployed into a specific subnet of your network called the 'GatewaySubnet'.The size of the GatewaySubnet that you specify depends on the VPN gateway configuration that you want to create. While it is possible to create a GatewaySubnet as small as /29, it is recommend to create a larger subnet that includes more addresses by selecting /27 or /28 to be able to accommodate future configurations.
In the "Create virtual network gateway" blade, configure the following:
Anyone knows a guide on how to implement this same VPN Tunnel Interface to Azure but with a backup connectivity into azure, from the same Sophos firewall, but on another WAN interface?
Our Sophos firewall is connected to 2 ISP providers, 1 on the WAN1 interface, and the other on WAN2 interface. Let us say that WAN2 is currently connected to Azure but if something happens to WAN2 we would like to have the connectivity failover to WAN1. WAN1 and WAN2 have 2 different public IP subnets provided by the ISP.
Hi Rob,
Thank you for reaching out to Sophos Community.
Kindly try the following
1. Establish a separate IPsec Tunnel using WAN1
2. Set an IPsec VPN Failover group using the Primary Tunnel and the second tunnel.
You can see references for the following:
Erick JanCommunity Support Engineer | Sophos Technical SupportSophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS AlertsIf a post solves your question use the 'Verify Answer' link.