I have a VPN IPsec tunnel between my two firewall sophos. I have a connection but no trafic. I made some firewall rules but I have nothing.
This is my schema.
And there are my rules:
Could someone help me ?
Thanks
Schönen guten Tag liebe Sophos Gemeinde. Ich würde gerne mal eure Meinung hören, da mich das Thema schon seit einiger Zeit verfolgt. Vielleicht weiß hier jemand, woran es tatsächlich liegt. Der Sophos Support konnte nur feststellen, dass eigentlich alles…
I have a Sophos model SFV1C4 with SFOS 19.5.2 MR-2-Build624
After the last firmware my site-to-site connections is timing out. It is Sonicwall that initiate the connections. I am using IKEv2 and after a while I get an error: ID 983 VPN IKEv2 Received…
Dead Peer Detection has a hidden design flaw.
Dead Peer Detection is a feature designed to retry\re-establish a tunnel when a tunnel drops. You can set 3 settings in this feature for 1)how long to wait before a retry, 2)how long to wait for a response…
Good day Folks,
I'm trying to get the following scenario to work for "STAS over IPSEC with authentication at Head office instead of branch":
1. User signs in at branch office
2. HEAD office firewall picks up or gets the authentication forwarded…
Dear Support;
I am using sophos xg firewall hardware device. I do IPSec configuration with AWS according to their configuration file. And follow Sophos Firewall: AWS VPN Gateway IPSEC Connection
I received the notice "IPsec connection could not be…
Hi,
i upgraded our XGS2100 from 19.5.2 to 19.5.3
We had a solid VPN Connection to a customer, after upgrading the Connection fails from time to time and VPN Log shows.
2023-08-28 10:11:14 IPSec Deny Received IKE message with invalid SPI (19CBD566…
Why can't you view your site-to-site settings when you have a failover group active. Whenever I'm working with a SOPHOS engineer on an issue, the first thing they want to do is view the VPN settings, but they can't without taking the VPN tunnel offline…
Hey All, ,
So i had something interesting that got fixed today.
On the old XG V17-19 when you create a IPSEC VPN, you didnt need to add a no NAT rule
(I could be mistaken if some one can confirm this)
But on the XGS, I had setup all the VPNs…
im having the problem with ipsec to a client with cisco firewall. The firewall cannot connect to the remote site but the policies and the satting are the same. This is how my setup is
Local Public ip : 154.120.225.2
Local ID : set as the Public ip…
Dear Community,
my name is david lorenz and I have a problem at one of our customers. At first I will describe my network situation. They have a HQ and a BO.
The HQ has the network: 192.168.2.0/24 (Sophos XG210 with 192.168.2.1)
The BO has the…
Hallo zusammen,
leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter.
Folgende Situatiion:
Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…
I have configured an IPSec VPN site-to-site connection between two sites, and after that, the ping traffic was going through between the sites. However, about 10 minutes later, when I pinged again to check, there were always a few initial packets that…
I currently have multiple tunnels on a SFV4C6MSP running on a cloud VM. I use this router to connect multiple IPsec tunnels to different customers.
These tunnels are setup as tunnel interfaces. and they will work fine for weeks, or months before one…
Hallo,
ich habe mal eine Frage. Also wie haben zwischen 2 Standorten eine Site-to-Site IPSec VPN Tunnel aufgebaut. Das klappte auch nach ein paar Schwierigkeiten recht gut. Allerdings haben wir nun das Problem, das wenn wir von Standort A nach Standort…
Hello,
Every 24 hours after the pppoe connection is reconnected, traffic stops passing through the tunnel.
My side is configured as a branch, has a dynamic ip address and initiates an ipsec connection.
After the wan ip address is changed, the tunnel…
Hello,
I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing.
What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my…
We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s.
- Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol?
Thanks André…
Hallo zusammen,
ich habe folgende Problematik und bin dort auf der Suche nach einer Lösung:
Wir haben mehrere Branch Office (BO) und binden diese über einen IPSec Tunnel an das Head Office (HO) an. Wir nutzen dazu im IPSec Tunnel das 1:1 NAT um…
I am using Unraid NAS on a remote site without public IP. It has support for Wireguard server. I assume there is also a wireguard client. Can this remote NAS connect to my Sophos XG appliance so I can remotely access the remote Unraid NAS? Is this called…
Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.
Table of Contents
Overview
About Akamai SIA
Hardware…
Anyone in the community has configured Sophos to Smoothwall site-to-site vpn? we have issues establishing the VPN connection between two sites
The Details for Phase 1 and Phase 2 are all matching
we created firewall rules on both ends
the status…
Hello,
I need help with tunnel configuration. For now I have working ipsec connection to remote 3rd party firewall and sd-wan route to route traffic coming from my network (172.19.19.0/24) to destination ip addresses through tunnel interface.
The…