Browse By Tags

  • Check Ipsec Vpn Status by Command Cli

    HI, I would need to retrieve the following information from the XG 135 Firewall via script: - VPN status node by node and child by child - restart the VPN if phase2 or phase1 is down Can you help me retrieve this information via commands? Thank you
  • LLMNR disabled - DNS resolution no longer works over VPN

    Hello all, We have deactivated LLMNR via GPO. After that we had the problem that users who work via VPN have more DNS problems. No problems could be found in the internal network. In 90% of the cases, internal resources can no longer be resolved.…
  • SSL VPN

    Hi, I have L2TP over IPsec VPN setup on our SG125W firewall and it's not the best as it adds a lot of overhead to the user's connection experience. So searched around on the internet and found this article for setting up SSL VPN using a RAIDUS server;…
  • Sophos Connect VPN client not connecting to remote Site-to-Site server

    Good day, Wonder if anyone can help me. Have a site-to-site tunnel with a remote server. The remote server is connected through a site-to-site tunnel to a different company so I don't have control on the remote side network. Now I am trying to get…
  • AWS Sophos IPSEC Connection _Not connecting

    Hello, help troubleshoot this IPSEC connection. I have two IPSEC connections on My Sophos ( XG210 ) to AWS first is on My Primary IP which has connected successfully even though it's slow. The Second one is on my Secondary IP which is our back…
  • AWS- Sophos Site-to-Site IPSEC Very Slow

    Hello, I have set up a site-to-site tunnel from our device XG210 to AWS, despite having less than 100ms on ping the connection is very slow, kindly advise what the issue could be the issue, since the setup is okay, and tunnels are connected.
  • "IPSEC with a private I

    "Good morning, everyone. My question is the following: I have a modem that performs NAT from the public IP and provides the firewall with a private IP 192.168.1.0/24. Is it possible to establish an IPSEC connection with another firewall using a private…
  • DNS request to DNS over Site2Site VPN

    Hello! We are using a Hardware Firewall XGS-2100 to connect to two datacenters running our AD Controller there. The AD is also our DNS Server. This worked fine for a long time. For some reason one of the VPN stopped working and one of the AD Controller…
  • VPN IPsec site-to-site connexion established but no trafic

    I have a VPN IPsec tunnel between my two firewall sophos. I have a connection but no trafic. I made some firewall rules but I have nothing. This is my schema. And there are my rules: Could someone help me ? Thanks
  • Site-to-Site IPSec IKEv2 VPN

    Schönen guten Tag liebe Sophos Gemeinde. Ich würde gerne mal eure Meinung hören, da mich das Thema schon seit einiger Zeit verfolgt. Vielleicht weiß hier jemand, woran es tatsächlich liegt. Der Sophos Support konnte nur feststellen, dass eigentlich alles…
  • Firewall VPN site-to-site Sophos GX and Sonicwall - dropping connection

    I have a Sophos model SFV1C4 with SFOS 19.5.2 MR-2-Build624 After the last firmware my site-to-site connections is timing out. It is Sonicwall that initiate the connections. I am using IKEv2 and after a while I get an error: ID 983 VPN IKEv2 Received…
  • Dead Peer Detection - Design Flaw and workaround

    Dead Peer Detection has a hidden design flaw. Dead Peer Detection is a feature designed to retry\re-establish a tunnel when a tunnel drops. You can set 3 settings in this feature for 1)how long to wait before a retry, 2)how long to wait for a response…
  • STAS over IPSEC with authentication at Head office

    Good day Folks, I'm trying to get the following scenario to work for "STAS over IPSEC with authentication at Head office instead of branch": 1. User signs in at branch office 2. HEAD office firewall picks up or gets the authentication forwarded…
  • Sophos XGS IPSec VPN split tunnel

    I am running Sophos XGS 19.5.2 MR-2-Build624 in an active / passive cluster. I have configured IPSec VPN for 150+ remote users. I have approximately 32 split tunnel networks (recently migrated from another vendors platform). I've noticed that once connected…
  • Sophos XG fail with issue "IPsec connection could not be established" with Tunnel interface AWS.

    Dear Support; I am using sophos xg firewall hardware device. I do IPSec configuration with AWS according to their configuration file. And follow Sophos Firewall: AWS VPN Gateway IPSEC Connection I received the notice "IPsec connection could not be…
  • V19.5.3 and HA-Cluster - VPN Fails "invalid SPI" after upgrading

    Hi, i upgraded our XGS2100 from 19.5.2 to 19.5.3 We had a solid VPN Connection to a customer, after upgrading the Connection fails from time to time and VPN Log shows. 2023-08-28 10:11:14 IPSec Deny Received IKE message with invalid SPI (19CBD566…
  • Site-to-site VPN - Why can't you view your settings when you have a failover group

    Why can't you view your site-to-site settings when you have a failover group active. Whenever I'm working with a SOPHOS engineer on an issue, the first thing they want to do is view the VPN settings, but they can't without taking the VPN tunnel offline…
  • IPSec Remote Access funktioniert nicht in internem WLAN

    Hallo zusammen, wir haben das Problem, dass sich unser VPN Clients (iOS IPADs mit IPSec VPN) nicht über das interne WLAN verbinden können. von außerhalb funktioniert die Verbindung problemlos. Eine SSL-VPN Verbindung funktioniert Problemlos ist aber…
  • VPN IPsec Remote Access - Apipa Gateway on End Devices

    Hello Everyone, I am enabling IPsec remote access VPN on my firewall XG, the problem is that every time when the clients establish the VPN connection, my clients are getting an Apipa IP address as a gateway and the traffic toward those two IP (172.1…
  • VPN Setup

    Hello community. I'm pretty green with setting up VPN's so I have been studying like mad over the last few days every Sophos article and video I could find to try and do this myself but I have hit a brick wall. I need to connect a remote workstation to…
  • IPSEC VPN traffic not passing passing through to DST IP

    Hey All, , So i had something interesting that got fixed today. On the old XG V17-19 when you create a IPSEC VPN, you didnt need to add a no NAT rule (I could be mistaken if some one can confirm this) But on the XGS, I had setup all the VPNs…
  • Bestimmte Netze routen ueber einen Site2Site Tunnel

    Hallo, ich habe folgende Situation: 2x Sophos UTM 2 Standorte verbunden über einen IPsec Site2Site Tunnel, automatic firewall rules enabled Standort 1: 192.168.240.0/24, UTM IP Address 192.168.240.254 Standort 2: 192.168.0.0/24 , UTM IP Address…
  • Ipsec site to site connection

    im having the problem with ipsec to a client with cisco firewall. The firewall cannot connect to the remote site but the policies and the satting are the same. This is how my setup is Local Public ip : 154.120.225.2 Local ID : set as the Public ip…
  • Need Help with Client IPSec VPN (Connect) in to Site2Site VPN IPSec Tunnel (Policy Based)

    Dear Community, my name is david lorenz and I have a problem at one of our customers. At first I will describe my network situation. They have a HQ and a BO. The HQ has the network: 192.168.2.0/24 (Sophos XG210 with 192.168.2.1) The BO has the…
  • Web Server hinter Site2Site nicht erreichbar

    Hallo zusammen, leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter. Folgende Situatiion: Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…