• Issue on site to site VPN

    SteveChung
    SteveChung
    Hello, I have a strange issue on site to site VPN between two Sophos XG firewall. The site to site VPN was built with class C subnets as below. Site A - 192.168.1.0/24 Site B - 192.168.8.0/24 The sophos XG firewall generated VPN rule on top permit…
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • IKEv2

    AdminJH AdminJH
    AdminJH AdminJH
    When will IKEv2 for Remote Access VPN be available?
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: VPN & SD-WAN Zero Downtime Failover - Best Practice Guide

    LuCar Toni
    LuCar Toni
    Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Product and Prerequisites …
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos-to-Meraki IPsec VPN Issue

    Zane Donaldson
    Zane Donaldson
    Hey All, I've created an IPsec tunnel between my Sophos XG unit and a Meraki. On the Sophos unit, the "Connection" dot is yellow and when I click for more info, it shows that only one of two subnets is accessible. Clearly, the IPsec settings are correct…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec connection

    MADHURA SAPATE
    MADHURA SAPATE
    please guide me for activation between two firewalls ipsec vpn connection ..
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec VPN Failover Groups between two firewalls

    SI Braveo
    SI Braveo
    Hello, everybody! Got a quick question for the experts out there. I'm trying to set up an IPsec VPN Failover Group between two XGS firewalls, HQ and Branch, each with two WAN connections. I created 4 tunnels (two for each WAN connection) and added them…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Telefonanlage hinter Sophos XGS

    EinMarco_DE
    EinMarco_DE
    Hallo zusammen, folgendes Thema bescheert uns aktuell graue Haare. Eventuell etwas Offtopic. Folgender Aufbau: 2 Internet Anschlüsse Kabel BW Business mit Fritz!Box Cable als Gateway. Dahinter die Sophos XGS. Hinter der Sophos befindet sich eine…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Routing system generated traffic via IPSEC with failover

    Patrick Moore ZA
    Patrick Moore ZA
    Hi all I have a site where the XGS2100 is currently set to authenticate against the local AD Domain Controller. The DC is planned to move off-site and so the XGS will need to authenticate to the DC via IPSEC - the DC will be hosted behind an OpnSense…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG IPSec Tunnel to UDM VLANs Connection Error

    Sheldon Trewin
    Sheldon Trewin
    Hi all, I have a working IPSec tunnel from my Sophos XG to my UniFi UDM at a remote site. I have many VLANS at the remote site. The XG can connect to the UDM default VLAN, but not any others. Does anyone have experience with this? Thanks!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec Site to Site VPN Disconnection

    Jason G
    Jason G
    Hello, I have setup a site to site IPsec VPN between a Sophos XG (Responder) & a DrayTek (Initiator) router. Everything is working as it should apart from a disconnection every so often. I believe this has something to do with the re-key event that…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Crear enrutamiento entre dos VPN

    Lluis Bigordà
    Lluis Bigordà
    Buenas, necesito ayuda, porque no consigo por mis medios.. La SubredLocal la llamaremos Subred1 Tengo un Sophos XG, que esta conectado a otro host a través de una IPsec "Interfaz de Tunel", la llamaremos Subred2. Luego tengo usuarios que se conectan…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site to Site VPN

    sherwin ramos
    sherwin ramos
    Greetings, We've set up a Site to Site VPN in our Main and branch office, they were active but we're still unable to ping the ip address from the main. Can anybody help me with this?? or any configurations i need to check please? thank you.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec connection is Down after migrating systems to another data center (WAN IP changed)

    cap admin
    cap admin
    The information provided by clients is as below From our admin side, we already amended the information such as local subnet and remote subnet as below except the interface wan1 Do we need to match the interface also? We do not know how…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • static routes disappear on tunnel Interface - VPN

    Brandon Gordon
    Brandon Gordon
    We have a configuration with out 30 tunnel interfaces to remote workers. These use static routes. On 5 or so of these configurations when the VPN tunnel reconnects the main firewall loses the routes. They still exist in the GUI, but in the CLI they are…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN TELTONIKA RUT240 and SOPHOS XGS

    Edvvde
    Edvvde
    Hello everyone, I have successfully established an IPSec site-to-site connection between a SOPHOS XGS firewall and a RUT240 from Teltonika. A ping from the Teltonika router to the SOPHOS firewall works. A ping to an end device behind the SOPHOS firewall…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC-SITE-TO_SITE (Unable to resolve %any)

    Verdigo
    Verdigo
    I'm having issue with my IPSEC-site-to-site connection. The IPSEC vpn cannot be established. Im having error " unable to resolve %any, retrying in 60s" when checking the strongswan.log Here is the full logs: loading secrets from '/_conf/ipsec/ipsec…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Destination Unreachable

    SATHEESH KOOLIPPILAKKAL
    SATHEESH KOOLIPPILAKKAL
    I have setup IP-Sec between head office and branch office few days back. My branch office is working perfectly fine and accessing all the resources on the head office but on the other hand when i try to access or ping any resource on branch office from…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Full tunnel site to site IPsec VPN bug

    Shunze Lee
    Shunze Lee
    Hi All, We have a question in Full tunnel site to site IPsec VPN. When we create a local 192.168.183.50/32 to remote Any site to site IPsec VPN. We found that XG's own routing will also be carried out through this VPN tunnel. There…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • What does „system ipsec_route“ really?

    kerobra
    kerobra
    Hi, maybe a dumb question but what does the command really do? Maybe it is because of my special setup with the BO firewall tunneling all traffic to the HO firewall. But as far as I understood the - very well hidden - comparison whenever I want to do…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • (S)NAT for IPSec Tunnel with a remote network in public IP range

    Quallensaft
    Quallensaft
    Hello, I need someone to help me across the road: I have a IPSec Tunnel (networks are just examples): Local network 192.168.100.0 /24 <-> Remote network 192.168.200.0 /24 I have also additional local networks: 192.168.1.0 /24 192.168.2.0 /24 192.168.3…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Routing between 2 Branch Offices

    Koumni Moussa
    Koumni Moussa
    Hello, I have 2 branch offices that are connected to the head office via VPN , now I want to connect these 2 offices to each other using the head office as a forward node, is that possible? if so please explain how PS: The branch offices don't have…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • About Ipsec site-to-site connectivity

    ab awal
    ab awal
    I am using XGS136 Firewall, Recently I restored a backup to XGS136 from XG 126. Now I fell to an issue that my ipsec site-to-site connectivity does not work properly, though the connectivity status is green. like site A user access site B, but site B…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN IPsec status of connection - monitoring via API/SNMP

    Roman Tucek
    Roman Tucek
    Hello, I would like ask , if somebody know , if will be option monitor VPN IPsec via snmp or API. I found , that is offen question in the forum. Sophos XG - SNMP - Monitor tunnel status Check Ipsec Vpn Status by Command Cli Read IPSec Connection…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to configure an IPsec VPN failover with 2 gateways on each end

    Lais Medeiros
    Lais Medeiros
    Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot. I thought about doing it like this: The Branch initiates…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Recommendations for Site2Site TunnelAll VPN

    kerobra
    kerobra
    We will have a special deployment at one customer soon. The customer has serveral branch offices where Sophos XGS 136 will be the local gateway for 5-6 subnets for each branch office. The BO firewalls will only have base subscriptions and only some…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
<>