• 2 WAN-Links (use primary one, and only if failover the second) - Problem with DNAT on failover Interface

    nils50122
    nils50122
    Hello, we have an question because in the past we have problems with DNAT when configuring our two WAN-links as active/passive. As a workaround we configured the two interfaces as active/active, but now the problem is the second link (which is limited…
    • 12 days ago
    • Sophos Firewall
    • Discussions
  • Sophos XG Firewall IPSec Failover to Azure.

    Sophos User6087
    Sophos User6087
    Hi all, I was hoping I can seek some guidance on this forum. Currently, we are using our Sophos XG Firewall to connect to our network on Azure using an IPSec VPN Tunnel. We do have two ISP running in our building one being main and other being backup…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • SD-WAN Connection Group and High Availability failover

    JakeSophos
    JakeSophos
    Hello, I am looking to confirm if the below is feasible. We have a HO and BO. The BO hosts a number of production servers and so there is an SD-WAN Connection Group that connects the two firewalls and allows certain services to certain VLAN networks…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • IPsec VPN Failover Groups between two firewalls

    SI Braveo
    SI Braveo
    Hello, everybody! Got a quick question for the experts out there. I'm trying to set up an IPsec VPN Failover Group between two XGS firewalls, HQ and Branch, each with two WAN connections. I created 4 tunnels (two for each WAN connection) and added them…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • DISABLE BACK UP WAN | DYNAMIC IP

    Marjoriel Ancog
    Marjoriel Ancog
    Hello, We have two ISPs set up for our client's firewall. The main one is static, and the other backup is dynamic. My concern is that if the failover ISP is on dynamic, that could prevent us from remotely getting into the firewall to switch the failover…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS 107w 4G WAN Fallback not working

    Aaron Berger
    Aaron Berger
    Hi, I've setup 4G WAN fallback if the primary NBN connection goes down. I've confirmed the 4G WAN connection is working. However, when the primary WAN connection goes down, it's not falling over to the 4G WAN. This is the failover rule I have in…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to configure an IPsec VPN failover with 2 gateways on each end

    Lais Medeiros
    Lais Medeiros
    Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot. I thought about doing it like this: The Branch initiates…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAN LINK Load balancing and failover

    Tharindu Premarathne
    Tharindu Premarathne
    Hi Guys, One of our customers has 3 ISP links and he needs to configure one ISP for the Active and the other two as a Backup line, When active links go down, we have to use both backup links to share the traffic. Is there any workaround for that scenario…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Update DDNS with current active gateway public IP

    Andrew Lynch
    Andrew Lynch
    I have two ISP's connected to my firewall, one is the dedicated WAN connection & the second is the failover WAN Connection. both have static IP's. I need an option to have the firewall update a single DDNS Address when the Dedicated WAN Connection fails…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Route Site-to-Site VPN over different ISP

    Werner Smit
    Werner Smit
    Good day, I've been struggling with this issue here for quite some time. We have a Site-to-Site VPN setup to external company with NATed ranges. Have setup the firewall to fail-over to backup ISP should the primary ISP fail. Trying tested it multiple…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • 3CX | Split DNS

    Tharindu Premarathne
    Tharindu Premarathne
    Hi Guys, One of our customers uses a 3CX system and has a separate MPLS connection for it. They bypassed the link to 3cx and accessed their 3cx server through the internet. Now they are requesting us to configure router traffic using the MPLS link…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG210 Failover

    Jim Fox
    Jim Fox
    We are adding Verizon boxes for failover port 3 static ip from ISP port2 Verizon DHCP, when I tested the failover today, the internet remained at the site, but i was not able to manage it from there portal. Has anyone else had experience with this?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAN access to few VLAN on backup link

    Amit
    Amit
    Hello all! I have a Sophos XGS firewall configured with one LAN and two WAN interfaces. The two WAN links are configured in failover mode, the backup link being activated when the primary one goes down. The backup link has limited bandwidth. I need…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SD-WAN IPSec xfrm routing/failover issues

    FFin
    FFin
    Hi, to get used to and evaluate sd-wan and xfrm-tunnel interfaces for seamless site2site vpn-connections, i setup two demo-sfos appliances (using home-license!). Site A WAN 1 to Site B WAN 1 & 2. Everything seems to be correct as i can RDP…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall can't switch on backup connection

    Kacper Zontek
    Kacper Zontek
    Hello, I have a problem with the backup link in Sophos. We received an LTE link that works and has the correct address set. The "Type" options were set to "Backup" and the "Activate on failure of" rule was set to the main link. The problem is that when…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN failover to Azure

    Daniel Zulian
    Daniel Zulian
    Hi, community. I have an issue with my failover VPN to Azure. I have an XG210 v19, connected to 2 ISPs. I have a VPN connection to Azure cloud for SAP services. As recommended for Sophos, I created the VPN as tunnel interface, with xfrm interfaces.…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos v19 Wan Link Manager - One active Two Backups

    Riccardo De Lazzari
    Riccardo De Lazzari
    Hi, I need a little help. I have client that has three WAN connection. One set to Active and two Backups. How can I choose which backup connection will take over first, if the Active one, fails? I have this option: but it let me choose only between…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • XG v19 WAN Link Manager: Error when updating Failover Rules

    Joshua Drost
    Joshua Drost
    I often receive the following error when trying to update a failover rule for one of my gateways: "Gateway failover rule could not be updated" I can't find any consistency in how to re-create this. I'm not sure if the problem also existed in v18.x…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAN Link Manager failover precedence

    Mitch Turner
    Mitch Turner
    The failover rule for a WAN link only allows for failover to "any available gateway." What if I want it to fail to a specific gateway, one that is active all the time? I have 3 WAN connections--these are ALL active connections ALL the time. Fios 1000…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • SOPHOS TO SOPHOS CONNECTIVITY AND WAN FAILOVER USING LOOPBACk

    Aliasgar Quettawala
    Aliasgar Quettawala
    GREETING!!! 1. I have site-1 and site-2 with there own sophos xg firewall connected to wan link on port-8, port-1 is on lan, and port-f1 uplink is connected on both sides. so what rule should i create to bypass the traffic from site 1 to site 2…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • SD-WAN Policy & Failover

    Adam T
    Adam T
    It sounds like I have a very specific use case that no one else has brought up in tutorials. I have two WAN links, one being the main gateway, and a LTE failover (we require this for our POS system). We consume a lot of data, and I don't want to overwhelm…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • XG 2. WAN failure kills outgoing network

    DAENG
    DAENG
    Hello, I have 2 WAN port as long both are working everthing is ok. But as soon my 2. Fritzbox is dead (Cable Fritzbox fails like once a year, but thats another story) there is no regular outgoing network anymore. In WAN Manager both are ok, in the…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAN link manager failed

    ITA_Fabio
    ITA_Fabio
    Hi everyone, I've just read some threads about similar problem without luck. My XG is configured with a primary wan as active and a second line as backup. I've configured a couple of SD-WAN rules to redir always on the second wan the traffic for some…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Multisite MPLS & VPN Tunnel Backup

    ibnuFajar
    ibnuFajar
    HI All Right now we implement MPLS with VPN as backup base on KB-000035833 document. Our MPLS connect with multiple site also VPN Tunnel connect to multiple tunnel to backup MPLS. As per document we need to add system link_failover add primarylink…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XG IPsec VPN automatic failback

    admin_idl
    admin_idl
    Hello, good day, We have an XG 230 with the version SFOS 18.0.5 MR-5 and have created an IPsec connection in a failover group. The switch between active and passive works. If the primary internet line is then active again, the automatic failback function…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
>