Hey All,
I've created an IPsec tunnel between my Sophos XG unit and a Meraki. On the Sophos unit, the "Connection" dot is yellow and when I click for more info, it shows that only one of two subnets is accessible.
Clearly, the IPsec settings are correct…
Hello, everybody! Got a quick question for the experts out there.
I'm trying to set up an IPsec VPN Failover Group between two XGS firewalls, HQ and Branch, each with two WAN connections. I created 4 tunnels (two for each WAN connection) and added them…
Hi all
I have a site where the XGS2100 is currently set to authenticate against the local AD Domain Controller. The DC is planned to move off-site and so the XGS will need to authenticate to the DC via IPSEC - the DC will be hosted behind an OpnSense…
Hi all,
I have a working IPSec tunnel from my Sophos XG to my UniFi UDM at a remote site. I have many VLANS at the remote site. The XG can connect to the UDM default VLAN, but not any others. Does anyone have experience with this? Thanks!
Hello,
I have setup a site to site IPsec VPN between a Sophos XG (Responder) & a DrayTek (Initiator) router. Everything is working as it should apart from a disconnection every so often. I believe this has something to do with the re-key event that…
Buenas,
necesito ayuda, porque no consigo por mis medios..
La SubredLocal la llamaremos Subred1
Tengo un Sophos XG, que esta conectado a otro host a través de una IPsec "Interfaz de Tunel", la llamaremos Subred2.
Luego tengo usuarios que se conectan…
Greetings,
We've set up a Site to Site VPN in our Main and branch office, they were active but we're still unable to ping the ip address from the main. Can anybody help me with this?? or any configurations i need to check please? thank you.
The information provided by clients is as below
From our admin side, we already amended the information such as local subnet and remote subnet as below except the interface wan1
Do we need to match the interface also? We do not know how…
Hello everyone,
I have successfully established an IPSec site-to-site connection between a SOPHOS XGS firewall and a RUT240 from Teltonika.
A ping from the Teltonika router to the SOPHOS firewall works. A ping to an end device behind the SOPHOS firewall…
I'm having issue with my IPSEC-site-to-site connection. The IPSEC vpn cannot be established. Im having error " unable to resolve %any, retrying in 60s" when checking the strongswan.log
Here is the full logs:
loading secrets from '/_conf/ipsec/ipsec…
I have setup IP-Sec between head office and branch office few days back. My branch office is working perfectly fine and accessing all the resources on the head office but on the other hand when i try to access or ping any resource on branch office from…
Hi All,
We have a question in Full tunnel site to site IPsec VPN. When we create a local 192.168.183.50/32 to remote Any site to site IPsec VPN.
We found that XG's own routing will also be carried out through this VPN tunnel.
There…
Hello,
I have 2 branch offices that are connected to the head office via VPN
, now I want to connect these 2 offices to each other using the head office as a forward node, is that possible? if so please explain how
PS: The branch offices don't have…
I am using XGS136 Firewall, Recently I restored a backup to XGS136 from XG 126. Now I fell to an issue that my ipsec site-to-site connectivity does not work properly, though the connectivity status is green. like site A user access site B, but site B…
Hello, I would like ask , if somebody know , if will be option monitor VPN IPsec via snmp or API. I found , that is offen question in the forum.
Sophos XG - SNMP - Monitor tunnel status
Check Ipsec Vpn Status by Command Cli
Read IPSec Connection…
Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot.
I thought about doing it like this:
The Branch initiates…
We will have a special deployment at one customer soon.
The customer has serveral branch offices where Sophos XGS 136 will be the local gateway for 5-6 subnets for each branch office. The BO firewalls will only have base subscriptions and only some…
Dear Community,
we have a customer with a XG Firewall in HQ and OPNSense in BA. Them are connected with IPSec PB S2S VPN. There is a older solved Case for more informations:
https://community.sophos.com/sophos-xg-firewall/f/discussions/141557/need…
Good day together
I normally look after Zyxel firewalls, but I was now allowed to take over a Sophos customer from a former colleague. I would like to switch this customer from IKEv1 to IKEv2, but I don't want to make a hard switch. So that the customer…
Good Day,
We have four site-to-site VPNs setup and working.
Site A (Head Office)
Site B (Branch Office 1)
Site C (Branch office 2)
Site D (External party (Fortinet) site)
Site A (Head Office) connects to Site D (external party) to allows…
IPSec Site-2-Site VPN
from initiator XGS to receiver SG firewall.
the XGS is on v19.5.3
IKEv1 (caused by SG capabilities)
Whenever someone rebooted the ISP router on the XGS site, the XGS will not re-initiate the connection and sits there disconnected…
Hi everyone,
we have an existing VPN Connection:
local subnet:
172.25.169.144/28
remote subnet:
172.25.169.104/29
no we have to translate every connection with destination 172.25.169.108 to our source ip 172.25.169.145.
i already tried…
Hi,
First of all, I tried to find existing discussions about the issue i'm facing but i'm not 100% sure I've searched/used the right keywords.
Let me explain:
I have 3 sites (let's call those SS, RR and DC).
SS subnet is: 172.42.23.0/24
RR s…
The IPSec tunnel comes up and is seen on both ends but not able to route traffic between the two. Tried to setup static routes, no change. What do I need to set on both ends to get the traffic to flow ??