• Firewall Cluster login to secondary over IPsec tunnel

    AlexanderPoettinger
    AlexanderPoettinger
    We have a series of customers with a firewall cluster but no local server infrastructure. Their resources are in our datacenter. There is always an IPsec tunnel from the datacenter to the firewall. We can always access the firewalls through the IPsec…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to clear IPSEC VPN SA via CLI on Sophos XGS?

    TorstenS
    TorstenS
    Hi, is it possible to clear single IPSEC VPN security associations via Device Console or Advanced Shell on Sophos XGS? E.g. I would like to disconnect all VPNs to one specific gateway. Thank you. Greetings, Torsten
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Can't establish a IPSEC tunnel btw Sophos XG and Fortigate

    juntacadaveres
    juntacadaveres
    Hello there. I have doing some labs and until now I have achieved to make a Sophos-Sophos and Forti-Forti Ipsec tunnel. However I am trying to make a Sophos XG-Fortigate IPSEC tunnel but my tunnel does not wake up. I have followed this guide and configure…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • kein IPsec VPN nach Upgrade auf SFOS 20.0.1 MR-1-Build342

    Uwe Bohnhoff
    Uwe Bohnhoff
    Hello, all our Site-to-Site-VPN don't work again after upgrading from SFOS 20.0.0 GA-Build222 to SFOS 20.0.1 MR-1-Build342. In the log we find: (unnamed) - Couldn't parse IKE message from .. Also all outgoing remote IPSec don't work again after…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • L2 Connection Between XGS2100

    DDL_123
    DDL_123
    I am having issues configuring a connection between two Sophos firewalls and i am hoping someone can help. The firewalls are installed in two datacenters which are operated by the same provider, both sites are currently configured with a WAN/internet…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Start IPsec connection via console

    SimpleCloud
    SimpleCloud
    I have an IPSec connection that I would like to start the connection via Console. Which commands do I need for this? I am referring to the second button that can be found next to Activate connection in the SFOS web interface.
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • IPSec Site-to-site VPN breaks every day at around 11AM

    Noni Scho
    Noni Scho
    We have an IPSec Site-to-site VPN that is supposed to connect our site with a couple servers hosted on Microsoft Azure. This worked fine for around 2 years, but since May, every day between 10:30 and 11AM the connection breaks and does not seem to re…
    • 6 months ago
    • UTM Firewall
    • General Discussion
  • site to site vpn

    faycal cod
    faycal cod
    Hi, I need help connecting the headquarters containing device ruijie rg-nbr6210-e and the branch containing device SOPHOS. I have made all the required settings, but there is no connection to find out more. I am at your disposal. Thank you.
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Set source IP for site to site IPSec VPN using 'Tunnel Interface' connection type linking multiple subnets

    JasP
    JasP
    We have multiple site to site VPNs setup with connection type 'Tunnel Interface'. The VPN links connect multiple remote subnets. How does XG pick a source IP because it seems to be random and can change when we re-establish a connection. This causes issues…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Route based VPN loopback

    Tony Steele
    Tony Steele
    I have a Route based VPN from SOPHOS to SOPHOS. I need to create a loopback to allow a connection back to a server. I am not able to find any information regarding this. In fact from what I can see I am not sure I can even do this with a normal IPSEC…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • No access to the web admin via VPN-NAT since V20 MR1 update

    schmiegi
    schmiegi
    Hello everyone, We are accessing a customer appliance via IPSEC-S2S VPN. Access is made to an IP that is NATed in the tunnel on the customer side and translated in the IPSec config on the customer side. Nothing special, has always worked. In addition…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS site-to-site SSL VPN static IP address for client

    VGDtech
    VGDtech
    Hello, I have Sophos XG 2300 with firmware 19.5.3 MR-3. I'm trying to set a static IP address for a site-to-site SSL VPN client. Is there any way to achieve this? Whatever I do it keeps getting leased IP address from Global DHCP pool or the VPN…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Received IKE message with invalid SPI (F5D1C2B8) from the remote gateway.

    Deepesh kumar jain
    Deepesh kumar jain
    Received IKE message with invalid SPI (F5D1C2B8) from the remote gateway. Received IKE message with invalid SPI (2AE78327) from the remote gateway. What could be the issue and how to solve it?
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Fortigate 80F v Sophos XG125 IPSec Remote Access

    BrushTech
    BrushTech
    With my license renewal fast approaching and my XG125 rev3 EOL I am at a cross roads as to which vendor I should move forward with. Out of pure frustration, I got my hands on a Fortigate 80F to compare SSLVPN and IPSecVPN remote access throughput. I setup…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Endpoint not able to browse over site to site VPN to backup target

    Mark Tarrant
    Mark Tarrant
    Hello, newbie here with Sophos. I am looking at a (new) client I have inherited who have their servers being backed up locally and then across a site to site VPN to a secondary location. There is one server on a different subnet that has never been…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN allows traffic to one subnet, but not another.

    ml17
    ml17
    I am trying to establish a Route based site-to-site IPSec VPN connection between two Sophos XG Firewalls (all fully up to date) - I followed this recipe . I have two subnets on the 'HeadOffice' Firewall - 192.168.22.0/24 and 192.168.23.0/24 and I have…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site connected but no traffic over failover GW

    Werner Smit
    Werner Smit
    Good day, On our XG230 [ SFOS 20.0.0 GA-Build222] we have two IPsec site-to-site tunnels on two different GWs. Both connect to the same remote GW but use Different NATed local Subnets to Fortigate Firewall. IPSec policies are the same no change there…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Keep Site-to-site Tunnel Connected?

    Zane Donaldson
    Zane Donaldson
    Hey All, I've created an IPsec tunnel between my Sophos XGS unit and a Meraki with the Sophos unit initiating the connection. Traffic is passing just fine, but the location where the Sophos unit is located has somewhat spotty internet. It appears…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Can`t acces Webadmin or SSH from IPSec VPN (Anymore)

    Maik Martin
    Maik Martin
    Hey everybody, i have a strange Problem. I have Firewall on Main Office and a Firewall in Azure (Both with Firmware SFOS 19.5.3) I have a working VPN and everything seems to be fine. But i cant access the Main Offices Web GUI or SSH CLI from…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Device on BO side of IPSec Site-to-site unable to ping HO side

    Werner van Niekerk
    Werner van Niekerk
    I have a scenario and trying to set something up for the interim. In essence, the requirement is to get an APP server at location A to connect to DB server in location B. The main issue with this is that both locations have the same subnet (E.g 172…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-site IPsec VPN with Mikrotik and Overlapping network

    Andrea C
    Andrea C
    Hi everyone, I'm having difficulty getting site to site IPsec to work properly with a Mikrotik device. Both LANs use the same class 192.168.99.0/24 and to configure the Sophos (SG115 SFOS 20.0.0 GA-Build222) I followed these instructions: https:/…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPSEC site-to-site connection

    admin_idl
    admin_idl
    Hello, We are trying to establish an IPSEC VPN connection between 2 XGs Firewall. There is a Fritzbox behind the firewall at both locations. We have already tested many different settings and policies but keep getting the following error message: …
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Fluctuating WAN IP with Dynamic DNS in Sophos Gateway Firewalls

    Mohammed Minhaz
    Mohammed Minhaz
    I was seeking a solution for an issue encountered with my client’s Sophos Gateway Firewall (Site-to-Site IPsec VPN Setup), which was due to the ISP’s PPPoE Service causing frequent changes in the WAN Interface IP. I’ve learned that Dynamic DNS could…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Dynamic WAN IP With IPSec Site to Site

    Mohammed Minhaz
    Mohammed Minhaz
    The client has a Sophos XGS107 in the branch office and an XGS2100 in the head office. We have site-to-site IPSec with PSK with HO to 2 BO. Due to the PPPoE WAN IP provided by the ISP, the firewall’s WAN interface IP changes frequently. We face a challenge…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • IPSec site-to-site with login/password authentication

    Alysko
    Alysko
    Hi, I'm trying to set up an IPSec VPN on a Sophos XG to connect as site-to-site to an internet box that serves as a IPSec (IKEv2) VPN server. When configuring a new VPN user, the box only gives username/password and VPN server address. Is it possible…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
<>