Browse By Tags

  • IPSEC-Tunnel funktioniert nicht seit Umstieg auf XGS

    Hallo zusammen, uns plagen etwaige Probleme seit wir von unserer guten alten Sophos ASG auf Sophos XGS umgeschwenkt sind. wir haben IP-Sec VPN Tunnel kreuz und quer durch ganz Deutschland, IKEv2, Verbindung ist da und es läuft Datentraffic darüber. Probleme…
  • Permitted network resources issue with SSL VPN

    Hi team , We have configured the SSL VPN in the firewall and allowed a single IP address in the permitted network resources, When we connect with VPN from other network, It will show the entire /24 network IP address as well as a single IP in the…
  • SSL Remote Access VPN Bridge with directly connected router

    Hello, I have a situation where i need to assign IP addresses to SSL remote access VPN clients from a certain subnet (10.10.10.0/24), and bridge the connection with a router (10.10.10.1) connected to a DMZ interface. I understand that the firewall assigns…
  • Sophos Firewall: SSL VPN - Auto Connect Client On Start-Up Using Provisioning File

    Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents: Overview Configuration Related Information…
  • Sophos Clientless SSL VPN RDP Bockmark

    Hi there, I am looking to configure a RDP Bockmark to allow our user to use the terminal servers on the road without using a VPN. Because of security reasons I want to use NLA, my question woud be is there any way to give the user the ability to change…
  • Firewall issue ping

    I recently add a new firewall for the branch office , so we have 2 firewalls one for the main office and one for the branch office, branch office can ping our ip's, but we from Main branch we can not ping any of their ip's, not even 1, it's really strange…
  • Frage Sophos SD-RED20

    Hallo ihr lieben, vielleicht hat jemand einen Rat für mich. Bis her haben wir eine Arzt-Praxis betreut, die eine Nebenbetriebsstätte hatte. Am Hauptstandort ist eine Sophos 107, die Nebenbetriebsstätte hatte eine SD-RED20. Die beiden Praxen teilen sich…
  • Sophos connect_2.3.2- installation issue.

    hi, i am trying to install SOPHOS connect but it is not being installed. detail is given below: Sophos connect_2.3.2-VPN.msi Microsoft Surface Laptop, 7th Edition Processor: Snapdragon(R) x 12 Core X1E80100 @ 3.40 GHz 3.42 GHz installed RAM: 16GB
  • Site-To-Site Sophos <-> AWS VPC: BGP Issues

    Hi, we have a site-to-site tunnel from Sophos Firewall to AWS. Several local (sophos side) networks are appearing in AWS routing tables correctly. However, the SSL-VPN network will not appear in AWS routing tables. When I check bgp information…
  • Site to Site VPN Authentication on reboots - Change PSK works

    I have multiple Sophos site to site VPN's back to a central router. Whenever any of the sites losing connection they all re-connect except for 1. The Sophos VPN logs show "Couldn't authenticate the local gateway. Check the authentication settings on both…
  • Firewall behind ISP Router

    Is there a way to check if the ISP router doesn't supports IKE2 causing IKE2 IPSEC tunnel to fail. A troubleshoot method or guide ? This is to proof to Service Providers that the problem lies in their end and not firewall.
  • XG firewall - Local ID for traffic

    Hello all, I currently have a XG firewall (FW-1), connected through IPSEC tunnel with another (FW-2). FW-1 has two LAN zones (LAN-A and LAN-B), both allowed through the IPSEC tunnel. FW-1 sends log messages (originated from the firewall itself…
  • ssl vpn query

    I have a question about SSL VPN auto connect. Can the user receive an automatic connection to the SSL VPN after restarting their computer and connecting to the internet?
  • Sophos Red 20 General Internet Access

    Hi, We have a RED 20 device that we recently purchased as a test device before looking to set multiple up across different sites, however we have found that our organisation's manual proxy blocks any internet access to anything not included in the proxy…
  • IPsec Remote Access not Receiving traffic

    I need some assistance please. Also i am new here, in the community. My ipsec remote access sends traffic but does not receive. See the screenshots of my configuration:
  • IPsec Site-to-Site VPN certain VLAN cant reach remote subnet

    Hi everyone, We have an IPsec site-to-site VPN connection between our Sophos and Fortigate devices. Currently, both the gateway and tunnel are UP and functioning properly. VLAN 10 and VLAN 20 are included in the local subnet configuration on the Sophos…
  • IPSec SG135 (9.719-3) vs XGS2100 (SFOS 20.0.0 GA-Build222)

    Very nice! I need help setting up an IPsec tunnel between sites, the firewall models are "UTM - SG135, Firmware 9.719-3" and "XGS2100 - Firmware (SFOS 20.0.0 GA-Build222)". We have researched through forums and followed some steps that match the errors…
  • problems with voip telephony, using site to site vpn connection

    implementing vpn site to site connection, causes problems with ip telephony, when starting the connection or disabling the connection causes my voip phones to start disconnecting from the pbx. once the connection is established and having the vpn connected…
  • Sophos SSL VPN not using first gateway

    Good Day, We have a remote SSL VPN setup for Sophos Connect clients to remote into our network when working from home. We have two GWs Primary GW1: IP:154.x.x.x Backup GW2: IP:105.x.x.x One user is currently experiencing issues with their ISP…
  • IPsec Connections using two Uplinks and DDNS

    Hello Community, here's the situation: Head Office (HO) : two WAN uplink connections, both have static IPs. One connection is 'cost based' and slower (backup WAN) and the other is quicker and has no traffic costs (primary WAN). Weights have been configured…
  • SSL VPN or ZTNA

    hi, i have friewall XGS2100 with Xstream protection. on that i am using ssl vpn for remote connectivity. so should i use ZTNA??? what extra benefits can i get if i use ZTNA?does xstream protection gives us few ZTNA licenses??? if i dont have Microsoft…
  • Ipsec and mss-clamping. Is there a way to make them persistent?

    Hi all, I have an xgs 3100 firewall on which about 20 ipsec tunnels are attested. All these ipsec have fragmentation problems so I am forced to use mss-clamping. For example without mss-clamping an icmp packet passes as long as I set a size of 1400…
  • Sophos VPN, Local SetuP

    Hi I am new to Sophos, I like to know about something Sophos VPN Local setup I have installed somehow sophos connect by a link provided in community, To use sophos vpn in my local machine, but i cant import anything because i cannot enter into the…
  • Sophos Client can´t import configuration file

    I have XGS 116 with 20.0.1 MR-1-Build342. Using a MAC computer, gets the "File Import Error" error when connecting to VPN using Sophos Connect, the same config file is processed on the device with the windows operating system and it works smoothly.…
  • RED vs IPSec (XGS)

    [POST DE DEBATE SOBRE O ASSUNTO] Opa pessoal! Em minha infraestrutura eu tenho o escritório na matriz (XGS 3100) conectado a outros quatro escritórios filiais (XGS 136) por Tunel RED, utilizando a configuração RED Server no escritório matriz e RED Client…