Browse By Tags

  • Site-to-Site VPN FritzBox -> Sophos XG

    I have established a VPN Tunnel between * Sophos XG (Head Office) * FritzBox (Branch Office) I can access Head Office Resources from Brach Office. But I cannot access the internet from Branch Office. I have created a Firewall Rule to allow Branch…
  • RDP freezes for 5-10 seconds

    So we have a pretty new XGS 2300 and we have some cases where we connect to our customers servers over an Ipsec Site-to-Site tunnel with RDP. the tunnel is stable but sometimes the remote desktop session freezes for a short time. I looked into the…
  • Connected to Sophos VPN has Internet but can't ping anything it always show ("Request Time out")

    there is internet before and after connecting vpn but every time I ping anything the result is always "Request time out". however after conecting to vpn the internet is slowing and cant ping servers Help me to fix this.
  • IPSec HA in 2 different data center

    Hi everyone, I have a challenge managing two firewalls (FW1 and FW2) in two different data centers (DC) that are far apart. In DC1, I use FW1 for IPSec tunnels with my clients. I want to add some details: We don't plan to use a FW cluster. We…
  • malformed payload in packet. Probable authentication failure (mismatch of preshared secrets?)

    I am trying to configure ipsec Site-to-site VPN between the Head and branch offices. The Head office is a Sophos UTM SG 210 configured as the responder (Repond-Only), and the branch Firewall is a Sophos XGS configured as the initiator. The Head office…
  • Looking for a "best practice" design or tips for multiple location/firewall authentication

    Hi, we have a customer, who has about 10 branch offices with each 5 to 50 users and a headquarter with about 50 users. Every BO has its own XGS firewall, which is currently connected via IPSEC VPN and will later be connected via MPLS to the HQ. In HQ…
  • unable to Allow Internet access from head office to branch office through mols VPN

    Good day we are using sophos firewall xgs 87 I have a problem. I want to allow the internet to go to all branch offices through the XG firewall at the head office. via ,mols vpn The other branch office has a Sophos firewall, Currently, I have…
  • IPSec site-to-site Reauthentication

    How do I enable reauthentication for site-to-site IPSec connections ? Sophos XGS3100, SFOS 19.5.3 MR-3-Build652
  • VPN IPsec site to site between Sophos and Fortigate

    Hello, I have to create several site-to-site IPsec between Fortigate Firewall and our Head Office Sophos Firewall. All connections must go to the same subnet in our Head Office. I've configured the Sophos as "Respond Only", the subnets are configured…
  • Unerklärliche Verbindungsunterbrüche

    Hallo zusammen Vielleicht hat jemand von euch noch eine Idee wo ich suchen kann oder was falsch ist. Wir haben auf 2 Sophos XGS107 immer wieder Verbindungsunterbrüche ins Internet. Das Problem ist das es nicht komplette Unterbrüche sind. Ich probiere…
  • VPN Site to Site - Questions about encryption

    Hello everyone, To configure a site-to-site VPN between two XGS 116, is it better to configure encryption as IKEV2 on both firewalls or DefautHeadOffice for the headquarters and DafautBranchOffice for the branch? Thanks André Soares
  • Only one way traffic ipsec site to site vpn

    I have a new Sophos XGS116 I have just installed replacing a Cisco ASA5506. (Site B) I setup the s2s with the same profile and settings (not subnet or public IP) as I use on another XGS116 (Site C) for the same customer. Both these 116s have a site…
  • Multiple IPSEC Tunnels with Combination of RSA and Preshared Keys.

    Been using 1 same preshared keys for over 10 sites that backhaul back to our HQ till now. However eversince v18 onwards, it's getting more and more unstable. After restarting our HQ Firewall, at least 3-4 sites tunnels wouldn't up. Ticked the create firewall…
  • Can't access remote server via IPSec s2s after migration (xg135w to xgs136)

    Hi, We have an IPSec s2s connection, and there is a remote subnet 10.0.0.0/255.255.255.0. Migration was done with configuration export/import and it seemed almost everything migrated successfully (only some firewall rules involvind ad users where…
  • User-IPsec-VPN per XAuth auf einer XGS mit Fremdsoftware wie z.B. "NCP Secure Entry Client" noch möglich?

    Guten Morgen SOPHOS-Community, wir verwenden bei uns in der Firma schon lange gerne den "NCP SecureEntry VPN Client" - Ein beständiger stablier IPsec-VPN-Client, der vorallem wie wir es brauchen übersichtlich sehr viele verschiedene Einwahlen beherbergen…
  • XFRM Interface Diagnostic

    2 XGS connected via ISP PTP fiber as primary. Each XGS has a second ISP which will be used for a IPSEC tunnel in case the primary link fails. Currently OSPF is in use. I have a IPSec VPN between 2 XGS using a tunnel. Both XFRM interfaces are 192…
  • Issue on site to site VPN

    Hello, I have a strange issue on site to site VPN between two Sophos XG firewall. The site to site VPN was built with class C subnets as below. Site A - 192.168.1.0/24 Site B - 192.168.8.0/24 The sophos XG firewall generated VPN rule on top permit…
  • IKEv2

    When will IKEv2 for Remote Access VPN be available?
  • Sophos Firewall: VPN & SD-WAN Zero Downtime Failover - Best Practice Guide

    Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Product and Prerequisites …
  • Sophos-to-Meraki IPsec VPN Issue

    Hey All, I've created an IPsec tunnel between my Sophos XG unit and a Meraki. On the Sophos unit, the "Connection" dot is yellow and when I click for more info, it shows that only one of two subnets is accessible. Clearly, the IPsec settings are correct…
  • ipsec connection

    please guide me for activation between two firewalls ipsec vpn connection ..
  • IPsec VPN Failover Groups between two firewalls

    Hello, everybody! Got a quick question for the experts out there. I'm trying to set up an IPsec VPN Failover Group between two XGS firewalls, HQ and Branch, each with two WAN connections. I created 4 tunnels (two for each WAN connection) and added them…
  • Telefonanlage hinter Sophos XGS

    Hallo zusammen, folgendes Thema bescheert uns aktuell graue Haare. Eventuell etwas Offtopic. Folgender Aufbau: 2 Internet Anschlüsse Kabel BW Business mit Fritz!Box Cable als Gateway. Dahinter die Sophos XGS. Hinter der Sophos befindet sich eine…
  • Routing system generated traffic via IPSEC with failover

    Hi all I have a site where the XGS2100 is currently set to authenticate against the local AD Domain Controller. The DC is planned to move off-site and so the XGS will need to authenticate to the DC via IPSEC - the DC will be hosted behind an OpnSense…
  • XG IPSec Tunnel to UDM VLANs Connection Error

    Hi all, I have a working IPSec tunnel from my Sophos XG to my UniFi UDM at a remote site. I have many VLANS at the remote site. The XG can connect to the UDM default VLAN, but not any others. Does anyone have experience with this? Thanks!