Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Web Server hinter Site2Site nicht erreichbar

    Hallo zusammen, leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter. Folgende Situatiion: Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…
  • Firewall Drop several initial packet from vpn site to site

    I have configured an IPSec VPN site-to-site connection between two sites, and after that, the ping traffic was going through between the sites. However, about 10 minutes later, when I pinged again to check, there were always a few initial packets that…
  • the received traffic selectors did not match: ::/0 === ::/0

    I currently have multiple tunnels on a SFV4C6MSP running on a cloud VM. I use this router to connect multiple IPsec tunnels to different customers. These tunnels are setup as tunnel interfaces. and they will work fine for weeks, or months before one…
  • Sophos XGS2100 Site-to-Site Tunnel Problem

    Hallo, ich habe mal eine Frage. Also wie haben zwischen 2 Standorten eine Site-to-Site IPSec VPN Tunnel aufgebaut. Das klappte auch nach ein paar Schwierigkeiten recht gut. Allerdings haben wir nun das Problem, das wenn wir von Standort A nach Standort…
  • Route based IPSec traffic stops passing xfrm disabled after pppoe reconnect

    Hello, Every 24 hours after the pppoe connection is reconnected, traffic stops passing through the tunnel. My side is configured as a branch, has a dynamic ip address and initiates an ipsec connection. After the wan ip address is changed, the tunnel…
  • IPSec strongswan creating CHILD_SA failed in logs

    Hello, I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing. What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my…
  • Site to Site VPN Issues Between Sophos XGS 116

    We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s. - Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol? Thanks André…
  • site to site VPN

    Dear Sophos Team, can we setup site to site VPN in same subnet?
  • DNS Request route over IPSec with NAT Translation

    Hallo zusammen, ich habe folgende Problematik und bin dort auf der Suche nach einer Lösung: Wir haben mehrere Branch Office (BO) und binden diese über einen IPSec Tunnel an das Head Office (HO) an. Wir nutzen dazu im IPSec Tunnel das 1:1 NAT um…
  • How do I connect a NAS that has Wireguard support to Sophos firewall?

    I am using Unraid NAS on a remote site without public IP. It has support for Wireguard server. I assume there is also a wireguard client. Can this remote NAS connect to my Sophos XG appliance so I can remotely access the remote Unraid NAS? Is this called…
  • Mysterious logs on all XG's with IPSEC VPN configuration

    Hi, Since a few days I see the same LOG entry on all XG Firewalls with active IPSEC VPN configuration. (I have checked more than 8 firewalls). The attempts come from the same IP 213.109.84.251 on all machines. Nslookup on this address returns the domain…
  • Sophos to Smooth wall Site to Site VPN connection

    Anyone in the community has configured Sophos to Smoothwall site-to-site vpn? we have issues establishing the VPN connection between two sites The Details for Phase 1 and Phase 2 are all matching we created firewall rules on both ends the status…
  • Sophos Firewall: Connect Akamai SIA and Sophos Firewall

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview About Akamai SIA Hardware…
  • VTI SNAT

    Hello, I need help with tunnel configuration. For now I have working ipsec connection to remote 3rd party firewall and sd-wan route to route traffic coming from my network (172.19.19.0/24) to destination ip addresses through tunnel interface. The…
  • Standortvernetzung SG310 mit XGS126

    Hallo zusammen, ich möchte unseren Hauptstandort (SG310) mit einer Zweigstelle (XGS126') vernetzen. Leider finde ich hierzu keine brauchbare Anleitung wie ich das ganze konfigurieren muss. Kann mir jemand weiterhelfen? Vielen Dank im voraus! …
  • Site to Site VPN best practice for multi-wan to multi wan

    Hi All, I inherited a SITE to SITE configuration that I believe is misconfigured. I am in hopes that I can get help to understand the best way to do this. It doesn’t seem right. Maybe I’m just missing a Failover group on the first site.? 1st XG125…
  • XFRM GATEWAY health check STATUS IS DOWN on both head office and branch office

    I have created ipsec tunnel to enable branch office to access head office, tunnel on both offices are 'up' but xfrm gateways on both sides which i have used in sdwan routing are 'down'. but by using diagnostic tool i can ping both xfrm interfaces but…
  • ipsec site-to-site vpn problem with dnat servers

    Hi, we have an XG135 in the headoffice and an XG87 in the branch office. in the headoffice we have two servers ( mail and something else ) that need to be reachable from the outside and we used the Server Accesss Assistant to create the correpsonding…
  • Sophos SG --> XGS IPSec Connection Terminated

    hi, we have the problem that an IPSec connection between SG and XGS shows Terminated status several times a day and then the status changes directly back to established and the connection continues to work without problems. What settings or logs should…
  • VPN IPSEC Site-to-site service times out in IKE phase until reboot

    Hello, We have the following scenario: Two Sophos XG310 with active-passive high availability enabled. Since we configure high availability from time to time, the site-to-site ipsec VPN service just stops working, 80% of our tunnels are disconnected…
  • IPSEC Setup with Zscaler

    hi all, we encountered some limitation with sophos fw, under SFOS 19.5 with IPSEC configuration. There is no possibility to set null encryption under ipsec phase 2 part. Is there a way to bypass this limitation ?
  • Can't access or ping IPSec Site-to-Site Local to Remote devices

    Hi, I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side Here's my config : Sophos XG - SFOS 19.5.2 MR-2-Build624 Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
  • IPSEC Sophos XG 18.5 (Nat configuration from tunnel)

    Hello, I got a IPSEC VPN from my sophos xg to remote firewall. Many subnet from my side are nated dynamiclaly with 172.30.10.0/24 to reach different subnet on the other side. Like (192.168.1.0/24 , 192.168.2.0/24 ...are nated with 172.30.10.0/24…
  • IPsec Remote access VPN and Other group memberships active directory

    Hello Team! In my environment, I have groups created in Active Directory to control remote access via VPN on the firewall. Turns out this VPN group I created in AD, in the firewall's webadmin when looking up the user, is listed in the Other group…
  • ipsec sophos utm sophos xgs

    Wir haben/hatten folgendes Problem: 2023:07:03-09:56:28 login-sp pluto[7264]: "S_Speyer-SPBZ-Koblenz"[4] xxx.xxx.xxx.xxx:4500 #203026: ignoring informational payload, type PAYLOAD_MALFORMED bei IPSEC zwischen Sophos UTM und XGS. Diese Meldungen…