• Site-to-site IPsec VPN with Mikrotik and Overlapping network

    Andrea C
    Andrea C
    Hi everyone, I'm having difficulty getting site to site IPsec to work properly with a Mikrotik device. Both LANs use the same class 192.168.99.0/24 and to configure the Sophos (SG115 SFOS 20.0.0 GA-Build222) I followed these instructions: https:/…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Connect Installation

    Pradeep
    Pradeep
    Hello All, Recently we are facing issue while installing sophos connect attached snip for your reference .please verify it and provide solution and help me to resolve this issue. Thanks in advance.
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Connect 2.3 with disabled IPv6 component

    Quallensaft
    Quallensaft
    - upgraded our Windows Connect Clients from 2.2.9 to 2.3 - when now connecting with SSL VPN: The client is connected (all is working) but the state in Sophos Connect will not switch to connected and stays in "is connecting"... -> not possible to disconnect…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • SSL VPN no Internet access

    NismoC32
    NismoC32
    I have set up a SSL VPN connection in SOHPOS Firewall v20 Build 222. I can access local services and machines no problems there, but I cant get internet access. When I ping external sources no packages comes through, however domain names are resolved…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPSEC site-to-site connection

    admin_idl
    admin_idl
    Hello, We are trying to establish an IPSEC VPN connection between 2 XGs Firewall. There is a Fritzbox behind the firewall at both locations. We have already tested many different settings and policies but keep getting the following error message: …
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Connect 2.3 cannot connect to Sophos UTM

    Oliver Regelmann
    Oliver Regelmann
    I upgraded my Sophos Connect client to the latest version 2.3 ( Sophos Connect 2.3 Update Released ) and since then cannot connect via SSL VPN to my UTM / SG230 obviously because of a cipher incompatibility. Client says Timeout openvpn.log says: …
    • 7 months ago
    • UTM Firewall
    • VPN: Site to Site and Remote Access
  • Fluctuating WAN IP with Dynamic DNS in Sophos Gateway Firewalls

    Mohammed Minhaz
    Mohammed Minhaz
    I was seeking a solution for an issue encountered with my client’s Sophos Gateway Firewall (Site-to-Site IPsec VPN Setup), which was due to the ISP’s PPPoE Service causing frequent changes in the WAN Interface IP. I’ve learned that Dynamic DNS could…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Dynamic WAN IP With IPSec Site to Site

    Mohammed Minhaz
    Mohammed Minhaz
    The client has a Sophos XGS107 in the branch office and an XGS2100 in the head office. We have site-to-site IPSec with PSK with HO to 2 BO. Due to the PPPoE WAN IP provided by the ISP, the firewall’s WAN interface IP changes frequently. We face a challenge…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • IPSec site-to-site with login/password authentication

    Alysko
    Alysko
    Hi, I'm trying to set up an IPSec VPN on a Sophos XG to connect as site-to-site to an internet box that serves as a IPSec (IKEv2) VPN server. When configuring a new VPN user, the box only gives username/password and VPN server address. Is it possible…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Country Restriction vpn ssl

    Alexander Vasquez
    Alexander Vasquez
    I have configured an SSL VPN to which I want to apply a restriction so that it only allows connections from Colombia, I have created the ACL allowing "Colombia" in the Source and selected the User Portal and SSL VPN services, after this I have disabled…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Policy-Based IPsec with Oracle Cloud Infrastructure(OCI)

    GiuseppeI
    GiuseppeI
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Note: The following KB is an updated version of the Sophos Firewall…
    • 7 months ago
    • Sophos Firewall
    • Recommended Reads
  • XGS IPSec S2S Azure and isolating a shared MAC Mini with SSL VPN Contractor

    WABGOR_DAVE
    WABGOR_DAVE
    Hello all, Network (kinda) and XGS newb is back with another question. I'm pretty sure the answer is going to be a "yes/no and you're just missing this little step to get it done". I've included a summarizing picture. Presently working: We have an…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • SSL VPN Performance is horrible using TCP or UDP

    Shawn Adams
    Shawn Adams
    We have 2 XG330 in HA, a 300Mbit connection and are using the SFOS 20.0.0 GA-Build222 firmware with Sophos Connect. Using the SSL VPN with UDP we are seeing speeds of 3.6Mbit down and 6.9Mbit up. The Client has 100Mbit. I've read a lot of different…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Possible bug: Issue in site to site VPN ipsec changing WAN interface

    eclipse79
    eclipse79
    Hello, I have an issue with site to site vpn IPSec. I suppose it is a bug. Scenario: You have 1 WAN port (port 2) You have some created site to site VPN IPSEC (initiate the connection type) Follow these steps to reproduce the issue: - Configure…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Remote Access SSL VPN Static IP address results in route issues

    Linh Phàng Tú Linh
    Linh Phàng Tú Linh
    Hello there I'm using version XGS2100 (SFOS 20.0.0 GA-Build222) and getting an error in SSL VPN Static IP When I use static IP for VPN user, the firewall cannot connect to the static ip of vpn user When i have the static IP Address disabled in my…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Erneuerung SSL Zertifikat für VPN?

    mbr_cfk
    mbr_cfk
    Wir verwenden im Unternehmen die Sophos Firewall und das Sophos Connect für den VPN-Zugang. Demnächst läuft eines unserer SSL-Zertifikate aus. Da ich noch recht unerfahren im Umgang mit Sophos bin, wollte ich nun wissen, ob das Auswirkungen auf unsere…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • German Forum
  • Sophos Connect 2.2 scx file gateway_order not working

    EastCoastUser
    EastCoastUser
    I have a Sophos that has a publicly accessible IP address which I will call 47.x.x.x, and this same IP is also publicly reachable via DNS name which I will call myhost.com. I have IPsec set up and working on my Sophos v20 firewall. I have Sophos Client…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • SSL VPN Sophos Connect failed

    Mohamed Said Ali
    Mohamed Said Ali
    We created SSL VPN from Sophos firewall But still connection from sophos connect not stablished, the indication error displayed by this message " DNS Resolution failed for gateway : Firewall DNS Name
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sophos 20 RED - power failure and quarantine (lockout)

    Jaakko Herttua
    Jaakko Herttua
    Hello! Power outage for a few days and now 20 RED locked or quarantined. How can I unlock it? And how (I need exact instructions)?
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN access

    EastCoastUser
    EastCoastUser
    I'm using the Home Firewall 20.0. I configured IPSec VPN using the Sophos instructional video. I used the default profile. I'm on the road, and trying to connect to devices on my home LAN, via the VPN. Let's call the LAN subnet X.X.X.0/24. The Sophos…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Multicast Forwarding issues

    Randy Cleveland
    Randy Cleveland
    We have recently set up Multicast forwarding between our main office and a remote location via a site-to-site vpn. The Multicast forwarding is working from the remote location back to the main office, however, the system we need to multicast in the…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Multicast Traffic Forwarding over IPSec vpn

    Randy Cleveland
    Randy Cleveland
    We are trying to forward multicast traffic for 239.1.1.2 between our Main Site to one of our remote sites via a Site-to-Site IPSec VPN connection. I have following the instructions here: https://support.sophos.com/support/s/article/KB-000038580?language…
    • Answered
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • SSLVPN Certificate renewals require re-download?

    ArtL
    ArtL
    I'm aware of the KB that states when it is required to re-download the SSLVPN configuration when changing global settings but it doesn't specify the certificate as one of these things. So what happens if you renew an active certificate before it expires…
    • Answered
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • IPSec tunnel interface for same interface WAN and remote adress 0.0.0.0

    Guilherme Silva1
    Guilherme Silva1
    Hello, Is there a way to configure a VPN tunnel interface scenario, using the same WAN interface to receive the connection from remote points? In this case, I have only 1 internet link on site A with a fixed IP, and I have several remote branches…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • IPSEC XG Failover

    admin_idl
    admin_idl
    Hello, We have set up an IPSEC connection and want to set up a failover. We have checked the connection of the backup IPSEC connection and the tunnel could also be established. However, if we use the IPSEC connection in a failover group as backup IPSEC…
    • 8 months ago
    • Sophos Firewall
    • Discussions
<>