Hi,
I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side
Here's my config :
Sophos XG - SFOS 19.5.2 MR-2-Build624
Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
Hello,
I got a IPSEC VPN from my sophos xg to remote firewall.
Many subnet from my side are nated dynamiclaly with 172.30.10.0/24 to reach different subnet on the other side. Like (192.168.1.0/24 , 192.168.2.0/24 ...are nated with 172.30.10.0/24…
Hello Team!
In my environment, I have groups created in Active Directory to control remote access via VPN on the firewall.
Turns out this VPN group I created in AD, in the firewall's webadmin when looking up the user, is listed in the Other group…
Wir haben/hatten folgendes Problem:
2023:07:03-09:56:28 login-sp pluto[7264]: "S_Speyer-SPBZ-Koblenz"[4] xxx.xxx.xxx.xxx:4500 #203026: ignoring informational payload, type PAYLOAD_MALFORMED
bei IPSEC zwischen Sophos UTM und XGS. Diese Meldungen…
We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script.
The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Episode #1
community.sophos.com/.../sophos-purposefully-designs-bugs-into-their-firewalls-episode-1---vpn-failover-and…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Episode 1
community.sophos.com/.../sophos-purposefully-designs-bugs-into-their-firewalls-episode-1---vpn-failover-and…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Our Background:
My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into.
Our Background:
My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
We have a Sophos firewall xgs 2300 v19.00, the firewall is configured VPN to branches, machine at the branch office are failing to activate ESET endpoint.. at the head office we have a ESET server
Hi,
Encountering a weird error when trying to attempt using a server for DNS forwarding.
We have a few branch offices - each connecting to DC via IPSEC (Connection Type: Site-to-Site / IKEv2) - with the DNS Forwadering Host in the DC.
Now here's…
Hi,
we are using sophos xg firewall we need to create one tunnel between two site both side sophos xg firewall.
head office having all server and ad and dc server also. so all user are in branch office access server head office and all internet traffic…
I am able to ping My my gateway from HQ which is my XG Firewall LAN interface ,but i am unable to ping anything in the LAN ,from Branch Router to HQ Router i have a GRE Tunnel,What do i need so that i am able to access LAN resources in Branch
Hallo zusammen.
Wir haben folgende Herrausforderung:
Wir haben bei einem Kunden eine SophosRED SG-20 am Standort 1. Diese soll einen VPN Tunnel zum Standort 2 mit einer Sophos XGS aufbauen. Dies funktioniert auch. Nun kommt die Herausforderung:…
Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using:
Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
Hi,
Apologies for the question, I've returned to using Sophos XG after exploring pfsense further again. With XG Home my understanding is it doesn't leverage to the cypto extensions on CPUs like pfsense, so "potentially" VPN performance might not be…
Can anyone tell me how i can stop this from happening?
The IP address is from Ukraine and nothing to do with this connection or s2s so I am a bit worried its some sort of attempted hack on port 500.
Ive put a block (drop) on the IP incoming but thats…
Hello All,
We have a site that has a FortiGate firewall at the main site and several old watchguard firewalls at remote site. We need to replace one on the firewalls at a remote site, hoping to replace all later, with a new XGS3100. Due to the current…
Hi to all,
I have a lot of connections attempts for the IPsec service:
Always from the same two or three IPs.
Is there any way to block all for IPsec except the remote IP of the tunnel?
Thanks in advance.
Best regards.
I have site-to-site connection from office to AWS VPC 1 another one from office to AWS VPC 2, using a firewall XG230 in office, what can be done to create a communication between AWS VPC1 and 2.
I am having difficulty routing across our vpn's. I need for Host1 and Hostt2 to be able to reach Alert11, Alert12, and Alert13 but currently that isn't happening. I can reach Gateway11, Gateway12 and Gateway13. The network looks like this:
NetworkA…
We have issue with IPsec configuration we create branch and headquarter vpn but not connect all setting is ok The main firewall is fiber connection The branch firewall is 5G router connection
Reply to chat and email / turky@thearchcapital.com
Hi.
I am currently working with a test environment and have configured two XG firewalls to have an IPSec Policy-based site-to-site connection between them. I cannot get the IPSec connection to forward traffic correctly. I have been trying for hours…
Hi,
We are losing our ipsec link after some time. (randomly)
Initial connection is ok no problem
But in logs we have this message : IPSEC FAILED Couldn't parse IKE message from : X.X.X.X Check the debugs logs ID 18052
If i reinitiate manually…
Hi,
we have a head office XG135 and 4 branch offices connected with site-to-site vpns and various sophos firewalls. ( 125, 87,86 ) VPNs are working fine.
We want to route all internt traffic from the branch offices through the headoffice internet…