• Sophos XGS2100 Site-to-Site Tunnel Problem

    Hans-Juergen Guenter
    Hans-Juergen Guenter
    Hallo, ich habe mal eine Frage. Also wie haben zwischen 2 Standorten eine Site-to-Site IPSec VPN Tunnel aufgebaut. Das klappte auch nach ein paar Schwierigkeiten recht gut. Allerdings haben wir nun das Problem, das wenn wir von Standort A nach Standort…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Route based IPSec traffic stops passing xfrm disabled after pppoe reconnect

    Carlo
    Carlo
    Hello, Every 24 hours after the pppoe connection is reconnected, traffic stops passing through the tunnel. My side is configured as a branch, has a dynamic ip address and initiates an ipsec connection. After the wan ip address is changed, the tunnel…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec strongswan creating CHILD_SA failed in logs

    Carlo
    Carlo
    Hello, I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing. What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site to Site VPN Issues Between Sophos XGS 116

    Andre Soares
    Andre Soares
    We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s. - Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol? Thanks André…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • site to site VPN

    Meghraj Gholap
    Meghraj Gholap
    Dear Sophos Team, can we setup site to site VPN in same subnet?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • DNS Request route over IPSec with NAT Translation

    Sven Blanke
    Sven Blanke
    Hallo zusammen, ich habe folgende Problematik und bin dort auf der Suche nach einer Lösung: Wir haben mehrere Branch Office (BO) und binden diese über einen IPSec Tunnel an das Head Office (HO) an. Wir nutzen dazu im IPSec Tunnel das 1:1 NAT um…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • How do I connect a NAS that has Wireguard support to Sophos firewall?

    jang430
    jang430
    I am using Unraid NAS on a remote site without public IP. It has support for Wireguard server. I assume there is also a wireguard client. Can this remote NAS connect to my Sophos XG appliance so I can remotely access the remote Unraid NAS? Is this called…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Connect Akamai SIA and Sophos Firewall

    DominicRemigio
    DominicRemigio
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview About Akamai SIA Hardware…
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos to Smooth wall Site to Site VPN connection

    Jamie Clague
    Jamie Clague
    Anyone in the community has configured Sophos to Smoothwall site-to-site vpn? we have issues establishing the VPN connection between two sites The Details for Phase 1 and Phase 2 are all matching we created firewall rules on both ends the status…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VTI SNAT

    Carlo
    Carlo
    Hello, I need help with tunnel configuration. For now I have working ipsec connection to remote 3rd party firewall and sd-wan route to route traffic coming from my network (172.19.19.0/24) to destination ip addresses through tunnel interface. The…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Standortvernetzung SG310 mit XGS126

    Michael Tholen
    Michael Tholen
    Hallo zusammen, ich möchte unseren Hauptstandort (SG310) mit einer Zweigstelle (XGS126') vernetzen. Leider finde ich hierzu keine brauchbare Anleitung wie ich das ganze konfigurieren muss. Kann mir jemand weiterhelfen? Vielen Dank im voraus! …
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Site to Site VPN best practice for multi-wan to multi wan

    Clay Wager
    Clay Wager
    Hi All, I inherited a SITE to SITE configuration that I believe is misconfigured. I am in hopes that I can get help to understand the best way to do this. It doesn’t seem right. Maybe I’m just missing a Failover group on the first site.? 1st XG125…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XFRM GATEWAY health check STATUS IS DOWN on both head office and branch office

    Jumanne Adam
    Jumanne Adam
    I have created ipsec tunnel to enable branch office to access head office, tunnel on both offices are 'up' but xfrm gateways on both sides which i have used in sdwan routing are 'down'. but by using diagnostic tool i can ping both xfrm interfaces but…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC Setup with Zscaler

    v h
    v h
    hi all, we encountered some limitation with sophos fw, under SFOS 19.5 with IPSEC configuration. There is no possibility to set null encryption under ipsec phase 2 part. Is there a way to bypass this limitation ?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec site-to-site vpn problem with dnat servers

    Kevin Stepper
    Kevin Stepper
    Hi, we have an XG135 in the headoffice and an XG87 in the branch office. in the headoffice we have two servers ( mail and something else ) that need to be reachable from the outside and we used the Server Accesss Assistant to create the correpsonding…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos SG --> XGS IPSec Connection Terminated

    admin_idl
    admin_idl
    hi, we have the problem that an IPSec connection between SG and XGS shows Terminated status several times a day and then the status changes directly back to established and the connection continues to work without problems. What settings or logs should…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN IPSEC Site-to-site service times out in IKE phase until reboot

    Camemiya
    Camemiya
    Hello, We have the following scenario: Two Sophos XG310 with active-passive high availability enabled. Since we configure high availability from time to time, the site-to-site ipsec VPN service just stops working, 80% of our tunnels are disconnected…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Can't access or ping IPSec Site-to-Site Local to Remote devices

    bcharles
    bcharles
    Hi, I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side Here's my config : Sophos XG - SFOS 19.5.2 MR-2-Build624 Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec sophos utm sophos xgs

    piddae
    piddae
    Wir haben/hatten folgendes Problem: 2023:07:03-09:56:28 login-sp pluto[7264]: "S_Speyer-SPBZ-Koblenz"[4] xxx.xxx.xxx.xxx:4500 #203026: ignoring informational payload, type PAYLOAD_MALFORMED bei IPSEC zwischen Sophos UTM und XGS. Diese Meldungen…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Need to re-input the Pre-shared key to establish Sophos to FortiGate

    sndyblz
    sndyblz
    We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script. The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SOPHOS Purposefully Designs bugs into their Firewalls: Episode 1 - VPN Failover and WAN Interfaces

    Steve Klassen
    Steve Klassen
    I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into. Our Background: My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ESET endpoint failing to activate

    Anesu Dangarembwa
    Anesu Dangarembwa
    We have a Sophos firewall xgs 2300 v19.00, the firewall is configured VPN to branches, machine at the branch office are failing to activate ESET endpoint.. at the head office we have a ESET server
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec

    satyabrata bastia
    satyabrata bastia
    Hi, we are using sophos xg firewall we need to create one tunnel between two site both side sophos xg firewall. head office having all server and ad and dc server also. so all user are in branch office access server head office and all internet traffic…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • UNABLE TO ACCESS SERVERS IN HQ LAN FROM BRANCH OFFICE

    Tarisai Dhombo
    Tarisai Dhombo
    I am able to ping My my gateway from HQ which is my XG Firewall LAN interface ,but i am unable to ping anything in the LAN ,from Branch Router to HQ Router i have a GRE Tunnel,What do i need so that i am able to access LAN resources in Branch
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec traffic no longer in VPN Zone?

    Thorben Paulik
    Thorben Paulik
    Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using: Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
<>