• Can’t route self-generated packets

    Rodrigue GRIMAUD
    Rodrigue GRIMAUD
    Hello, I work on 2 Sophos XG on 2 different sites. They communicate with each other using a Site-to-Site IPSec VPN. Site A : Sophos-XGS 33100 (SFOS 19.5.3) Site B : Sophos-XG 330 (SFOS 19.5.3) 3 subnets of Sophos A are configured to be able…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • on Sophos Firewall, if I update and regenerate the default CA, what are the implications?

    Callum Roseneder1
    Callum Roseneder1
    On Sophos Firewall, if I update and regenerate the default CA, what are the implications? I have a firewall that is setup, the default CA hasn't been customised so far. I need to setup a S2S IPsec VPN with certificates and wanted to customise this before…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Firewall Policy with Limited Access no Working

    CreateShare
    CreateShare
    Hi, I have two WAN Links. Firewall rules and sd-wan routes are created. If I add a new firewall policy to allow internet for a server that is not included in the default policy, it does not work. I created a new nat policy and sd-wan rule, but it did…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Unable to connect Digibox/Bintec Router to Sophos XG via IPsec

    Michael Orthen
    Michael Orthen
    Hello, I'm unable to connect a Telekom Digibox (branded Bintec Router) to a Sophos XG via IPsec VPN. charon.log of the Sophos Firewall: 2024-02-16 12:26:17Z 28[NET] <9> received packet: from <branch ip>[500] to <head ip>[500] (512 bytes) 2024-02…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • DHCP requests not routing over IPSEC

    Stuart James
    Stuart James
    I have a DHCP server running at head office on 192.168.100.21 which is a Windows Server that has a Sophos as it's gateway The branch office has a Sophos There is an IPSEC tunnel between the two Sophos units The branch office has a DHCP relay pointing…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Unable to establish the site to site communication between sophos firewall to Microtik router

    Anurag Murali
    Anurag Murali
    We set a local ip to our branch office 13.1 to the microtik switch and configured the IP sec in sophos firewall and established the connection and connection also up. We created the policies in microtik and added the IP address. Then established the connection…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • XGS126 gpupdate took a very long time via VPN

    Steve Reschke
    Steve Reschke
    Hello, we switched from a Zyxel Firewall to a XGS126 . Sinced we switched we have the problem, that gpudate takes a lot of time SSL UDP: 6-10 minutes SSL TCP: >30 minutes IPSec: 6-10 minutes In firewallrules we opened from VPN to LAN all…
    • 9 months ago
    • Sophos Firewall
    • German Forum
  • SOPHOS 2 BRANCH CONNECTION

    TimothyWanume
    TimothyWanume
    Hello I have two branches, both with Sophos firewalls. I have run fibre between these branches; how should I connect them so that they share resources? I have configured a site-to Site VPN, but what if one side loses internet? I need a backup.
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Site to Site IPSEC Conection with Selectet Clients

    Roger Domig
    Roger Domig
    Hello dear Sophos Forum, I have set up a Site-to-Site VPN connection between a NAS and 2 ESXi servers with a Sophos XGS. Setting up the connection was no problem, but I still can't reach the ESXi servers from the NAS, even though every port is allowed…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Vendor router/ipsec tunnel on /29 routed subnet behind /30 sophos xg. Tunnel disconnecting.

    Andrew Schoonover
    Andrew Schoonover
    Summary: AT&T provides us a /30 for our equipment and a /29 routed subnet. We are currently using several of these addresses as Alias NAT'd for hosted services. We have a vendor who wants to establish a VPN tunnel to their remote site via a cisco 4300…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • VPN IPsec Tunnel mit Internetzugang über eine Firewall

    Wolfgang Ritter1
    Wolfgang Ritter1
    Hallo Ich habe zwei Firewalls Head Office (Bach) und Filiale (Dornbirn) XG135 SFOS 19.5 Die WAN und Router Adressen sind in der Grafik nicht real. Bach: Ist hinter einem router welcher im bridge mode arbeitet. Das WAN interface ist nicht direkt…
    • 10 months ago
    • Sophos Firewall
    • German Forum
  • POLICY BASED IPSEC VPN with Source NAT (MASQ)

    Callum Roseneder1
    Callum Roseneder1
    I'm migrating from a UTM to an XG so i'm trying to replicate a config that already existed. I have the IPSEC VPN setup and the tunnel comes up. The VPN selector on my side only has a /30 I need to have the rest of the organisation talk through this VPN…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Using public IPs in different locations with IPSEC

    Christian Garcia N
    Christian Garcia N
    Good morning. I don't know if someone can help me as I have been trying various configurations and conducting tests without any success, and I'm not sure if the XG allows what I need. I have 2 offices: Office A has a public IP addressing (e.g.,…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site VPN FritzBox -> Sophos XG

    Jan Schumann
    Jan Schumann
    I have established a VPN Tunnel between * Sophos XG (Head Office) * FritzBox (Branch Office) I can access Head Office Resources from Brach Office. But I cannot access the internet from Branch Office. I have created a Firewall Rule to allow Branch…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • RDP freezes for 5-10 seconds

    VTH
    VTH
    So we have a pretty new XGS 2300 and we have some cases where we connect to our customers servers over an Ipsec Site-to-Site tunnel with RDP. the tunnel is stable but sometimes the remote desktop session freezes for a short time. I looked into the…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Connected to Sophos VPN has Internet but can't ping anything it always show ("Request Time out")

    Apo Lakay
    Apo Lakay
    there is internet before and after connecting vpn but every time I ping anything the result is always "Request time out". however after conecting to vpn the internet is slowing and cant ping servers Help me to fix this.
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • IPSec HA in 2 different data center

    Farzan Barouj
    Farzan Barouj
    Hi everyone, I have a challenge managing two firewalls (FW1 and FW2) in two different data centers (DC) that are far apart. In DC1, I use FW1 for IPSec tunnels with my clients. I want to add some details: We don't plan to use a FW cluster. We…
    • 10 months ago
    • UTM Firewall
    • General Discussion
  • malformed payload in packet. Probable authentication failure (mismatch of preshared secrets?)

    Izuchukwu Edeh
    Izuchukwu Edeh
    I am trying to configure ipsec Site-to-site VPN between the Head and branch offices. The Head office is a Sophos UTM SG 210 configured as the responder (Repond-Only), and the branch Firewall is a Sophos XGS configured as the initiator. The Head office…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Looking for a "best practice" design or tips for multiple location/firewall authentication

    kerobra
    kerobra
    Hi, we have a customer, who has about 10 branch offices with each 5 to 50 users and a headquarter with about 50 users. Every BO has its own XGS firewall, which is currently connected via IPSEC VPN and will later be connected via MPLS to the HQ. In HQ…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • unable to Allow Internet access from head office to branch office through mols VPN

    Anesu Dangarembwa
    Anesu Dangarembwa
    Good day we are using sophos firewall xgs 87 I have a problem. I want to allow the internet to go to all branch offices through the XG firewall at the head office. via ,mols vpn The other branch office has a Sophos firewall, Currently, I have…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • IPSec site-to-site Reauthentication

    osterhagen
    osterhagen
    How do I enable reauthentication for site-to-site IPSec connections ? Sophos XGS3100, SFOS 19.5.3 MR-3-Build652
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • VPN IPsec site to site between Sophos and Fortigate

    Boris Brunel
    Boris Brunel
    Hello, I have to create several site-to-site IPsec between Fortigate Firewall and our Head Office Sophos Firewall. All connections must go to the same subnet in our Head Office. I've configured the Sophos as "Respond Only", the subnets are configured…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Unerklärliche Verbindungsunterbrüche

    M B9
    M B9
    Hallo zusammen Vielleicht hat jemand von euch noch eine Idee wo ich suchen kann oder was falsch ist. Wir haben auf 2 Sophos XGS107 immer wieder Verbindungsunterbrüche ins Internet. Das Problem ist das es nicht komplette Unterbrüche sind. Ich probiere…
    • 10 months ago
    • Sophos Firewall
    • German Forum
  • VPN Site to Site - Questions about encryption

    Andre Soares
    Andre Soares
    Hello everyone, To configure a site-to-site VPN between two XGS 116, is it better to configure encryption as IKEV2 on both firewalls or DefautHeadOffice for the headquarters and DafautBranchOffice for the branch? Thanks André Soares
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Only one way traffic ipsec site to site vpn

    PeteH
    PeteH
    I have a new Sophos XGS116 I have just installed replacing a Cisco ASA5506. (Site B) I setup the s2s with the same profile and settings (not subnet or public IP) as I use on another XGS116 (Site C) for the same customer. Both these 116s have a site…
    • 10 months ago
    • Sophos Firewall
    • Discussions
<>