Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • About Ipsec site-to-site connectivity

    I am using XGS136 Firewall, Recently I restored a backup to XGS136 from XG 126. Now I fell to an issue that my ipsec site-to-site connectivity does not work properly, though the connectivity status is green. like site A user access site B, but site B…
  • VPN IPsec status of connection - monitoring via API/SNMP

    Hello, I would like ask , if somebody know , if will be option monitor VPN IPsec via snmp or API. I found , that is offen question in the forum. Sophos XG - SNMP - Monitor tunnel status Check Ipsec Vpn Status by Command Cli Read IPSec Connection…
  • how to configure an IPsec VPN failover with 2 gateways on each end

    Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot. I thought about doing it like this: The Branch initiates…
  • Recommendations for Site2Site TunnelAll VPN

    We will have a special deployment at one customer soon. The customer has serveral branch offices where Sophos XGS 136 will be the local gateway for 5-6 subnets for each branch office. The BO firewalls will only have base subscriptions and only some…
  • GRE tunnel local gateway config error

    Hi all, I got the following error when I tried to configure GRE tunnel on my Sophos FW (v19.5, home). console> system gre tunnel add name GRE1 local-gw Port1 % Error: Unknown Parameter 'Port1' The WAN port I am trying to configure GRE is Port1,…
  • IPSec S2S Policy Based VPN (btw. XG and OPNSense) - Routing Problems

    Dear Community, we have a customer with a XG Firewall in HQ and OPNSense in BA. Them are connected with IPSec PB S2S VPN. There is a older solved Case for more informations: https://community.sophos.com/sophos-xg-firewall/f/discussions/141557/need…
  • Two IKE VPN configurations on one firewall

    Good day together I normally look after Zyxel firewalls, but I was now allowed to take over a Sophos customer from a former colleague. I would like to switch this customer from IKEv1 to IKEv2, but I don't want to make a hard switch. So that the customer…
  • Relay traffic from branch office site-to-site to remote site through head office

    Good Day, We have four site-to-site VPNs setup and working. Site A (Head Office) Site B (Branch Office 1) Site C (Branch office 2) Site D (External party (Fortinet) site) Site A (Head Office) connects to Site D (external party) to allows…
  • XGS to SG UTM IPSec VPN not reconnecting, staying in disconnected state forever (IKEv1)

    IPSec Site-2-Site VPN from initiator XGS to receiver SG firewall. the XGS is on v19.5.3 IKEv1 (caused by SG capabilities) Whenever someone rebooted the ISP router on the XGS site, the XGS will not re-initiate the connection and sits there disconnected…
  • Hide NAT

    Hi everyone, we have an existing VPN Connection: local subnet: 172.25.169.144/28 remote subnet: 172.25.169.104/29 no we have to translate every connection with destination 172.25.169.108 to our source ip 172.25.169.145. i already tried…
  • Routing through an IPSec VPN

    Hi, First of all, I tried to find existing discussions about the issue i'm facing but i'm not 100% sure I've searched/used the right keywords. Let me explain: I have 3 sites (let's call those SS, RR and DC). SS subnet is: 172.42.23.0/24 RR s…
  • Site to Site XGS-126 to UniFi USG-Pro-4 not routing

    The IPSec tunnel comes up and is seen on both ends but not able to route traffic between the two. Tried to setup static routes, no change. What do I need to set on both ends to get the traffic to flow ??
  • Hinzufügen weiteres Netzwerk zu einem S2S VPN

    Hallo, ich habe da mal eine frage zu S2S VPN. Bin da nicht so sicher in der Einstellung von VPN und Firewall Regeln in ein bestehendes System. Ich habe hier ein laufendes System zwischen 2 Standorten und an dem einen Standort funktioniert es auch…
  • Remote Access VPN (SSL) over IPSec

    Hi all, i have the following issue and hope that someone can give me a hint or two: We're using a remote access connection (SSL VPN) to our Sophos XG. On the Sophos XG, we have an IPSec tunnel to another router (pfsense). Both work great. Now, we…
  • XG310v3 HA Active/Standby site-to-site VPN connections, 19.5.3. Unable to edit, delete or change status.

    Figured as since I cannot find anyone else experiencing this issue, wanted to highlight this here if it helps someone else or if Sophos want to investigate themselves. FW type, config and version in subject. TLDR: Disable HA if you experience issues with…
  • Sophos XG behind Fortigate firewall

    Dear Support, we set up a Fortigate firewall 200F at our edge and replaced the Sophos XG 210 we previously used. However, I have a remote site connected via RED devices, I decided to just continue using the RED device and move the Sophos XG behind the…
  • Sophos S2S ipsec -XGS107(branchOffice) <>XG330(HeadOffice)

    Hello, I have two sophos: - XGS107 as branchOffice (19.5.3) - XG330 as HeadOffice (19.5.2) I am experiencing strange behavior on "route-base" ipsec tunnel. Tunnel status on both sites is down but on HeadOffice i can see that connectio is UP. HeadOffice…
  • NAT multiple networks in an Ipsec tunnel

    Hello everyone, I have an IPsec connection to our holding with NAT, the fake local network is provided to us by the holding and can only be one. The problem is that I also have to convey other secondary networks to the tunnel, so I was thinking of doing…
  • IPSEC Site-to-Site - Multiple Local Subnets

    We have an XGS 2100 with an IKE2 IPSEC Site-to-Site connection to Azure. When initiating the connection, the "Flat LAN" subnet mounts but the various VLAN's bound to the "flat LAN" don't come up. The VLAN's are used for SIP phones and WiFi access…
  • Route-Based VPN - xfrm disabled

    Hallo Miteinander Ich habe ein Problem mit einer site-to-site VPN Verbindung. Die Ausgangslage war das ich zwei XG135 SFOS 19.5 so verbinde das ich den ganzen Datentransfer über den Hauptsitz führe und dadurch beide LAN Netze (192.168.10.0 und 192.168…
  • dual redundant vpn tunnels from branch office to HQ office

    I spent some time on research here and I wasn't able to find something like How-To, KB artice covering this scenario where we may have Sophos LTE modem on branch office or Teltonika modem attached to port. We do local break out for internet services…
  • Route Site-to-Site VPN over different ISP

    Good day, I've been struggling with this issue here for quite some time. We have a Site-to-Site VPN setup to external company with NATed ranges. Have setup the firewall to fail-over to backup ISP should the primary ISP fail. Trying tested it multiple…
  • IPSec traffic not tunneled

    Hi, there is a IPSec tunnel not tunneling traffic to remote site. Traffic from remote site to my site is sent trough tunnel as expected, but traffic to remote site is being nated and sent trough WAN interface. Remote site has to use my internet…
  • Activate and deactivate IPsec connection via CLI

    Hi, i read this post RE: Activate and deactivate IPsec connection via CLI It's what i need, but into Api documentation i can't see anything about this command, could you send me a documentation on info about this command? Thanks
  • Check Ipsec Vpn Status by Command Cli

    HI, I would need to retrieve the following information from the XG 135 Firewall via script: - VPN status node by node and child by child - restart the VPN if phase2 or phase1 is down Can you help me retrieve this information via commands? Thank you