Disclaimer: Please contact Sophos Professional Services if you require assistance with your specific environment.
1. XG v18 firmware
2. Your OnPrem XG Firewall and the following information:
3. Your Microsoft Azure vNet and the following information:
The local network gateway typically refers to your on-premises location. You'll need the public IP address of your On-Prem Sophos XG firewall and your On-Prem Private IP address spaces. Please note that this configuration assumes that the public IP address is directly configured on the On-Prem XG firewall. Your configuration will be slightly different if your On-Prem XG firewall sits behind a NAT device.
The local network gateway typically refers to your on-premises location. You'll need the public IP address of your On-Prem Sophos XG firewall and your On-Prem Private IP address spaces.
Please note that this configuration assumes that the public IP address is directly configured on the On-Prem XG firewall. Your configuration will be slightly different if your On-Prem XG firewall sits behind a NAT device.
In the "Create local network gateway" blade, configure the following and then click on "Create":
The VPN gateway will be deployed into a specific subnet of your network called the 'GatewaySubnet'.The size of the GatewaySubnet that you specify depends on the VPN gateway configuration that you want to create. While it is possible to create a GatewaySubnet as small as /29, it is recommend to create a larger subnet that includes more addresses by selecting /27 or /28 to be able to accommodate future configurations.
In the "Create virtual network gateway" blade, configure the following:
Hello Adam,
Make sure you’re clicking under your WAN interface that connects to the Azure, it might not show, until you click a white space on the WAN interface.
Regards,
Hello,
I have been working through this guide to setup a IPsec VPN connection and I can't get it to establish a connection.
I believe I am having difficulty with step 5. I am supposed to enter the APIPA address in the xfrm virtual port? What about the VPN connection? I assume this should be the public IP address of the azure Virtual Network Gateway for both. The guide is not very clear. I don't know why I would ever use an APIPA address. Unless someone can explain to me.
Sam
Hello, yes you need to put the 169.254.0.1 in the xfrm interface. The IP addresses for the VPN configuration are the public IP address of the on-premise Sophos Firewall and the Azure Virtual Network Gateway.