• IPSEC Setup with Zscaler

    v h
    v h
    hi all, we encountered some limitation with sophos fw, under SFOS 19.5 with IPSEC configuration. There is no possibility to set null encryption under ipsec phase 2 part. Is there a way to bypass this limitation ?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Can't access or ping IPSec Site-to-Site Local to Remote devices

    bcharles
    bcharles
    Hi, I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side Here's my config : Sophos XG - SFOS 19.5.2 MR-2-Build624 Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec Remote access VPN and Other group memberships active directory

    Guilherme Silva1
    Guilherme Silva1
    Hello Team! In my environment, I have groups created in Active Directory to control remote access via VPN on the firewall. Turns out this VPN group I created in AD, in the firewall's webadmin when looking up the user, is listed in the Other group…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Need to re-input the Pre-shared key to establish Sophos to FortiGate

    sndyblz
    sndyblz
    We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script. The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SOPHOS Purposefully Designs bugs into their Firewalls: Episode 1 - VPN Failover and WAN Interfaces

    Steve Klassen
    Steve Klassen
    I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into. Our Background: My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ESET endpoint failing to activate

    Anesu Dangarembwa
    Anesu Dangarembwa
    We have a Sophos firewall xgs 2300 v19.00, the firewall is configured VPN to branches, machine at the branch office are failing to activate ESET endpoint.. at the head office we have a ESET server
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec

    satyabrata bastia
    satyabrata bastia
    Hi, we are using sophos xg firewall we need to create one tunnel between two site both side sophos xg firewall. head office having all server and ad and dc server also. so all user are in branch office access server head office and all internet traffic…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • UNABLE TO ACCESS SERVERS IN HQ LAN FROM BRANCH OFFICE

    Tarisai Dhombo
    Tarisai Dhombo
    I am able to ping My my gateway from HQ which is my XG Firewall LAN interface ,but i am unable to ping anything in the LAN ,from Branch Router to HQ Router i have a GRE Tunnel,What do i need so that i am able to access LAN resources in Branch
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec traffic no longer in VPN Zone?

    Thorben Paulik
    Thorben Paulik
    Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using: Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG Home VPN (SSL Vs IPSEC)

    MikeyS
    MikeyS
    Hi, Apologies for the question, I've returned to using Sophos XG after exploring pfsense further again. With XG Home my understanding is it doesn't leverage to the cypto extensions on CPUs like pfsense, so "potentially" VPN performance might not be…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Couldnt parse IKE message

    PeteH
    PeteH
    Can anyone tell me how i can stop this from happening? The IP address is from Ukraine and nothing to do with this connection or s2s so I am a bit worried its some sort of attempted hack on port 500. Ive put a block (drop) on the IP incoming but thats…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec connection attempt

    BAD
    BAD
    Hi to all, I have a lot of connections attempts for the IPsec service: Always from the same two or three IPs. Is there any way to block all for IPsec except the remote IP of the tunnel? Thanks in advance. Best regards.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG v19.5.2 ipsec VPN routing problems

    MarkThornton
    MarkThornton
    I am having difficulty routing across our vpn's. I need for Host1 and Hostt2 to be able to reach Alert11, Alert12, and Alert13 but currently that isn't happening. I can reach Gateway11, Gateway12 and Gateway13. The network looks like this: NetworkA…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Vpn IPsec issue

    Arch Capital
    Arch Capital
    We have issue with IPsec configuration we create branch and headquarter vpn but not connect all setting is ok The main firewall is fiber connection The branch firewall is 5G router connection Reply to chat and email / turky@thearchcapital.com
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site IPSec Not Working As Intended

    haydenspence
    haydenspence
    Hi. I am currently working with a test environment and have configured two XG firewalls to have an IPSec Policy-based site-to-site connection between them. I cannot get the IPSec connection to forward traffic correctly. I have been trying for hours…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 210 IPSEC DOWN FAILED PARSING IKE

    Simon BALAND
    Simon BALAND
    Hi, We are losing our ipsec link after some time. (randomly) Initial connection is ok no problem But in logs we have this message : IPSEC FAILED Couldn't parse IKE message from : X.X.X.X Check the debugs logs ID 18052 If i reinitiate manually…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Internet traffic not routed from branch office through head office via site-to-site VPN

    brucepott
    brucepott
    Hi, we have a head office XG135 and 4 branch offices connected with site-to-site vpns and various sophos firewalls. ( 125, 87,86 ) VPNs are working fine. We want to route all internt traffic from the branch offices through the headoffice internet…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec to Azure - Tunnel interface missing after creation

    Matthew Wall
    Matthew Wall
    Hi all, I have been having an issue with my XG330 firewall. I created a Tunnel Interface to Azure, and see that the IPSec tunnel is not appearing under my network interfaces. I have followed the documentation highlighted here. Sophos Firewall: Configuring…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos to Fortigate site to site issue

    sndyblz
    sndyblz
    Anyone has a experience on create a site to ste vpn with fortigate firewall (as spokes and Sophos as hub), and face the ff issue: Random instances the spoke site went down even the isp has stable connection. And every time one or 2 sites (spoke, we…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC VPN intermittent communication issue

    Mayuresh Bhagwat
    Mayuresh Bhagwat
    Setup: Sophos XGS 87 (SFOS 19.5.1 MR-1-Build 278) and Sophos XG210 (SFOS 19.5.1 MR-1-Build278) Connection type: IPSEC VPN Site to Site Issue: The communication between the 2 site networks works well for sometime and suddenly the communication breaks…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • New S2S can't connect

    Jeff Vandervoort
    Jeff Vandervoort
    MO: XGS136/SFOS v19,5,2. Not in production yet, setting up to replace production firewall. BO: XG115/SFOS v19.5.2. In production. MO & BO have had an IPSec S2S running for a long time with the MO production firewall. The MO XGS that will replace…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site 2 Site VPN with multiple remotes having dynamic WAN IP addresses

    Randy Cleveland
    Randy Cleveland
    Hello, We have an XGS firewall at our HQ location, set up with several Site to Site VPN connections with remote XGS firewalls that have Static WAN IP addresses. I also have one site2site set up with a remote location with a dynamic WAN ip address…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Hub and Spoke with Sophos as HO and Fortigate as Branches

    sndyblz
    sndyblz
    We will migrate our Fortigate to Sophos XG, and one of our requirement is to create a IPsec site to site with Sophos XG 3300 ( as HUB or Head office) to small FortiGate in client branches (as Spoke). The problem is, I don't see any KB/Doc about creating…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec (Using NAT) add multiple local network

    Tier1@Vision9
    Tier1@Vision9
    Hello, We have created the IPSec tunnel (uses NAT) to application provider dc. Internal network is translated to NAT IP (provided by application provider). Tunnel is working. Now, we have to add SSL vpn remote access network to that IPSec tunnel…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN Ipsec Site-to-site

    Adem SI
    Adem SI
    Hi. I have a site-to-site ipesc tunnel with my branch, the tunnel is connected to both parts, I have two rules created, Inbound and Outbound rule, the inbound rule works perfectly, all clients on the branch network can connect to my servers, but the…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>