• SD WAN config between CGW and AWS EC2 Virtual FW

    Matt Carter
    Matt Carter
    Hi all, we currently have 20 sites all using Sophos XG107 or XG 117 FW. all sites have a S2S VPN connection into AWS for SMB access. issue we have is failover internet, if failover is required then our VPN drops due to new IP. Failover internet is…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPSec Recommended Settings for Branch Office

    CreateShare
    CreateShare
    Hi, Are there any specific IPSec Profile recommendations for connecting the branch office that does not have a static real IP Address? I am currently using the DefaultBranchOffice profile, but it disconnects automatically after some time. Thanks.
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Add subnets to NAT with policy-based IPsec when local and remote subnets are the same

    Mark Tarrant
    Mark Tarrant
    Hello all, I have a situation with a IPsec VPN setup between two sites that have subnets that are the same. I followed these instructions and it worked ok; NAT with route-based IPsec when local and remote subnets are the same - Sophos Firewall However…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • IPSEC/L2TP with Radius and CVE-2024-3596

    Dieter
    Dieter
    Hello, with the patch from Microsoft KB5040434 07/2024 there are problems with Radius authentication for L2TP. Without the patch, the client connection works without any problems. What can we do? Best Regards Dieter
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Site to site VPN to a vendor site with the same subnet at both ends

    Mark Tarrant
    Mark Tarrant
    Hello all, we are looking at a situation where we need to set up a site to site VPN to a vendor who is using a Fortigate gateway, and the same subnet is being used at both ends. I have reviewed the below link which covers this situation for Sophos to…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • XFRM showing 'not configured' after public IP changes on spoke

    GJN
    GJN
    Hello, we are currently using Sophos Firewalls in a Hub-and-Spoke topology running SFOS 20.0. Some spokes are using WAN connections with dynamic IPs which will change from time to time. On those units we can observe that the corresponding XFRM interface…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPESEC to Fortinet Firewall

    admin_idl
    admin_idl
    Hello, We are having problems establishing an IPSEC tunnel between an XGS and a Fortigate firewall. Currently we receive the message “IKE SA proposals don't match. Check the phase 1 policy settings on both devices: IKE:AES_CBC_256/HMAC_MD5_96/PRF_HMAC_MD5…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Disable IPSEC Anti Replay Protection SFOS v20

    OliverKnights
    OliverKnights
    Hello, Im trying to test out Cloudflare magicwan and the guide says to disable ipsec anti replay protection. The guide shows a command for sfos v19 however this doesn't seem to exist in v20. The command is: set vpn ipsec-performance-setting anti…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPSEC PSK and remote ID issue

    admin_idl
    admin_idl
    Hello, we have set up several Policy Based IPSEc tunnels. These have different remote gateways, but some of them have the same remote IDs. Some connections crash after a certain time. Could this be due to the PSK in conjunction with the remote ID? As…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Trouble routing a packet from site A via site B to site C (with SNAT)

    apijnappels
    apijnappels
    I have something strange for the following situation. VPN connection between site A and site B (tried both policy-based and route-based) and a policy-based VPN-connection between site B and site C. Intention is to reach site C from site A while there…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • User Authentication over S2S IPSec VPN

    CV_Sophos
    CV_Sophos
    We have currently have two locations, each with a XG330 v19.5.4 MR4 and an EPL fiber connection between them that has a S2S IPSec tunnel setup and a static route on both ends pointing to the other. Each FW is setup with the local DC for user authentication…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Site2Site IPSec VPN with both endpoints only IPv6

    Björn Bendix
    Björn Bendix
    Hello, I want to setup a S2S IPsec VPN between our Head office and Branch Office. The branch office has only IPv6. I have setup on btoh side the S2S VPN, but i cant get it to connect. And i even dont see any connection trys in the logs. For all other…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • IPSEC Failover for LAN Gateway

    Sandra Koehler
    Sandra Koehler
    I don't know if this is the right configuration so bear with me. I have a connection that essentially functions as a direct ethernet line back to the main office, called an EPLAN. It is set up in my Branch Office in the LAN zone. Everything works OK…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Connect 2.3 MR1 iPSec DNS problems but SSL OK

    StefanS
    StefanS
    Hi there, After the firmware update to SFOS 20.0.1 MR-1-Build342, we have rolled out the Sophos Connect Client v2.3.1. It turns out that DNS resolution does not work with IPsec. It looks like the wrong DNS servers are being entered here (ipv6). With SSL…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • IPSec MOBIKE IKEv2 extension disabling

    Jaroslav Faldik
    Jaroslav Faldik
    How can I disable MOBIKE IKEv2 extension support in IPSec?
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Firewall Cluster login to secondary over IPsec tunnel

    AlexanderPoettinger
    AlexanderPoettinger
    We have a series of customers with a firewall cluster but no local server infrastructure. Their resources are in our datacenter. There is always an IPsec tunnel from the datacenter to the firewall. We can always access the firewalls through the IPsec…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to clear IPSEC VPN SA via CLI on Sophos XGS?

    TorstenS
    TorstenS
    Hi, is it possible to clear single IPSEC VPN security associations via Device Console or Advanced Shell on Sophos XGS? E.g. I would like to disconnect all VPNs to one specific gateway. Thank you. Greetings, Torsten
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Can't establish a IPSEC tunnel btw Sophos XG and Fortigate

    juntacadaveres
    juntacadaveres
    Hello there. I have doing some labs and until now I have achieved to make a Sophos-Sophos and Forti-Forti Ipsec tunnel. However I am trying to make a Sophos XG-Fortigate IPSEC tunnel but my tunnel does not wake up. I have followed this guide and configure…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • kein IPsec VPN nach Upgrade auf SFOS 20.0.1 MR-1-Build342

    Uwe Bohnhoff
    Uwe Bohnhoff
    Hello, all our Site-to-Site-VPN don't work again after upgrading from SFOS 20.0.0 GA-Build222 to SFOS 20.0.1 MR-1-Build342. In the log we find: (unnamed) - Couldn't parse IKE message from .. Also all outgoing remote IPSec don't work again after…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XG Firewall IPSec Failover to Azure.

    Sophos User6087
    Sophos User6087
    Hi all, I was hoping I can seek some guidance on this forum. Currently, we are using our Sophos XG Firewall to connect to our network on Azure using an IPSec VPN Tunnel. We do have two ISP running in our building one being main and other being backup…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • L2 Connection Between XGS2100

    DDL_123
    DDL_123
    I am having issues configuring a connection between two Sophos firewalls and i am hoping someone can help. The firewalls are installed in two datacenters which are operated by the same provider, both sites are currently configured with a WAN/internet…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Start IPsec connection via console

    SimpleCloud
    SimpleCloud
    I have an IPSec connection that I would like to start the connection via Console. Which commands do I need for this? I am referring to the second button that can be found next to Activate connection in the SFOS web interface.
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • site to site vpn

    faycal cod
    faycal cod
    Hi, I need help connecting the headquarters containing device ruijie rg-nbr6210-e and the branch containing device SOPHOS. I have made all the required settings, but there is no connection to find out more. I am at your disposal. Thank you.
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Set source IP for site to site IPSec VPN using 'Tunnel Interface' connection type linking multiple subnets

    JasP
    JasP
    We have multiple site to site VPNs setup with connection type 'Tunnel Interface'. The VPN links connect multiple remote subnets. How does XG pick a source IP because it seems to be random and can change when we re-establish a connection. This causes issues…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Route based VPN loopback

    Tony Steele
    Tony Steele
    I have a Route based VPN from SOPHOS to SOPHOS. I need to create a loopback to allow a connection back to a server. I am not able to find any information regarding this. In fact from what I can see I am not sure I can even do this with a normal IPSEC…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>