• IPsec traffic no longer in VPN Zone?

    Thorben Paulik
    Thorben Paulik
    Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using: Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG Home VPN (SSL Vs IPSEC)

    MikeyS
    MikeyS
    Hi, Apologies for the question, I've returned to using Sophos XG after exploring pfsense further again. With XG Home my understanding is it doesn't leverage to the cypto extensions on CPUs like pfsense, so "potentially" VPN performance might not be…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Couldnt parse IKE message

    PeteH
    PeteH
    Can anyone tell me how i can stop this from happening? The IP address is from Ukraine and nothing to do with this connection or s2s so I am a bit worried its some sort of attempted hack on port 500. Ive put a block (drop) on the IP incoming but thats…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • OSPF over IPSec to FortiGate firewall

    Steve Deviller
    Steve Deviller
    Hello All, We have a site that has a FortiGate firewall at the main site and several old watchguard firewalls at remote site. We need to replace one on the firewalls at a remote site, hoping to replace all later, with a new XGS3100. Due to the current…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec connection attempt

    BAD
    BAD
    Hi to all, I have a lot of connections attempts for the IPsec service: Always from the same two or three IPs. Is there any way to block all for IPsec except the remote IP of the tunnel? Thanks in advance. Best regards.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • aws site to site

    Ricardo Madrid
    Ricardo Madrid
    I have site-to-site connection from office to AWS VPC 1 another one from office to AWS VPC 2, using a firewall XG230 in office, what can be done to create a communication between AWS VPC1 and 2.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG v19.5.2 ipsec VPN routing problems

    MarkThornton
    MarkThornton
    I am having difficulty routing across our vpn's. I need for Host1 and Hostt2 to be able to reach Alert11, Alert12, and Alert13 but currently that isn't happening. I can reach Gateway11, Gateway12 and Gateway13. The network looks like this: NetworkA…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Vpn IPsec issue

    Arch Capital
    Arch Capital
    We have issue with IPsec configuration we create branch and headquarter vpn but not connect all setting is ok The main firewall is fiber connection The branch firewall is 5G router connection Reply to chat and email / turky@thearchcapital.com
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site IPSec Not Working As Intended

    haydenspence
    haydenspence
    Hi. I am currently working with a test environment and have configured two XG firewalls to have an IPSec Policy-based site-to-site connection between them. I cannot get the IPSec connection to forward traffic correctly. I have been trying for hours…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 210 IPSEC DOWN FAILED PARSING IKE

    Simon BALAND
    Simon BALAND
    Hi, We are losing our ipsec link after some time. (randomly) Initial connection is ok no problem But in logs we have this message : IPSEC FAILED Couldn't parse IKE message from : X.X.X.X Check the debugs logs ID 18052 If i reinitiate manually…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Internet traffic not routed from branch office through head office via site-to-site VPN

    brucepott
    brucepott
    Hi, we have a head office XG135 and 4 branch offices connected with site-to-site vpns and various sophos firewalls. ( 125, 87,86 ) VPNs are working fine. We want to route all internt traffic from the branch offices through the headoffice internet…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec to Azure - Tunnel interface missing after creation

    Matthew Wall
    Matthew Wall
    Hi all, I have been having an issue with my XG330 firewall. I created a Tunnel Interface to Azure, and see that the IPSec tunnel is not appearing under my network interfaces. I have followed the documentation highlighted here. Sophos Firewall: Configuring…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos to Fortigate site to site issue

    sndyblz
    sndyblz
    Anyone has a experience on create a site to ste vpn with fortigate firewall (as spokes and Sophos as hub), and face the ff issue: Random instances the spoke site went down even the isp has stable connection. And every time one or 2 sites (spoke, we…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC VPN intermittent communication issue

    Mayuresh Bhagwat
    Mayuresh Bhagwat
    Setup: Sophos XGS 87 (SFOS 19.5.1 MR-1-Build 278) and Sophos XG210 (SFOS 19.5.1 MR-1-Build278) Connection type: IPSEC VPN Site to Site Issue: The communication between the 2 site networks works well for sometime and suddenly the communication breaks…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • New S2S can't connect

    Jeff Vandervoort
    Jeff Vandervoort
    MO: XGS136/SFOS v19,5,2. Not in production yet, setting up to replace production firewall. BO: XG115/SFOS v19.5.2. In production. MO & BO have had an IPSec S2S running for a long time with the MO production firewall. The MO XGS that will replace…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Webserver Protection for Host behind IP tunnel

    Linus Haake
    Linus Haake
    Hello everybody, I'm currently trying to establish the WAF setup for the current confirguration: Two sites are connected via IP Tunnel and everything is properly working with the static routes set-up. Now we have the need to setup Webserver Protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site 2 Site VPN with multiple remotes having dynamic WAN IP addresses

    Randy Cleveland
    Randy Cleveland
    Hello, We have an XGS firewall at our HQ location, set up with several Site to Site VPN connections with remote XGS firewalls that have Static WAN IP addresses. I also have one site2site set up with a remote location with a dynamic WAN ip address…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Hub and Spoke with Sophos as HO and Fortigate as Branches

    sndyblz
    sndyblz
    We will migrate our Fortigate to Sophos XG, and one of our requirement is to create a IPsec site to site with Sophos XG 3300 ( as HUB or Head office) to small FortiGate in client branches (as Spoke). The problem is, I don't see any KB/Doc about creating…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG Firewall - IPSEC VPN MFA ISSUE with OTP PIN

    Martin Hampl
    Martin Hampl
    Hi, I have XG125 (SFOS 19.5.1 MR-1-Build278) and IPSEC Remote Access for the users with internal OTP MFA. Remote users started to report disconnecting the VPN during the day, BUT also the need for MFA PIN to be entered multiple times a day. For example…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec (Using NAT) add multiple local network

    Tier1@Vision9
    Tier1@Vision9
    Hello, We have created the IPSec tunnel (uses NAT) to application provider dc. Internal network is translated to NAT IP (provided by application provider). Tunnel is working. Now, we have to add SSL vpn remote access network to that IPSec tunnel…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN Ipsec Site-to-site

    Adem SI
    Adem SI
    Hi. I have a site-to-site ipesc tunnel with my branch, the tunnel is connected to both parts, I have two rules created, Inbound and Outbound rule, the inbound rule works perfectly, all clients on the branch network can connect to my servers, but the…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Read IPSec Connection Status via API

    Franz Kempf
    Franz Kempf
    Hello, I was able to Active/DeActive an IPSec Connection via API (See the following thread) Activate and deactivate IPsec connection via CLI What I am not able to do is to read the actual status of the IPSec Connection. I was able to read out the…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF for Web-Server behind IPsec-Connection

    SM-ITM
    SM-ITM
    Hello, I have the problem with an XGS 107 (19.5.2-B624) that a web server (10.203.111.101), which is located behind an IPsec connection, is not reachable via the WAF. When accessing the web server via the Internet, I get the code 503. However, the problem…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Devices behind RED20 can not Access Server within Site 2 Site VPN connected by XG

    Sebastian Engler
    Sebastian Engler
    Hi friends, today I'm facing a fancy issue with one of our smaller customers. We try to connect to an RDP-Server within a Site2Site VPN. From XG LAN we are able to connect to the RDP-Server with any client within the LAN-Zone. Now we need to get…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall Authentication to server in Azure across VPN Tunnel

    DavidSain
    DavidSain
    I recently worked through a problem where an on premise firewall was unable to authenticate Remote Access VPN users with Active Directory as the server is hosted in Azure through a VPN (Active Directory is used instead of AAD as it's less expensive to…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>