I've built out in the SD-WAN connection group. XGS116 firewall at my remote home office is behind DHCP public IP. Virtual firewall in Azure is behind Azure's NAT. It doesn't seem like an SD-WAN Connection group can handle this as it configures the Gateway…
Good Day Members, I Trust you are well. We currently have 5 sites with site to site SSL VPN configured. We are investigating SD-WAN connection Group in Sophos Central. This will assist us in setting a couple defaults policies that that would be the same…
Dear Community,
we have a customer with a XG Firewall in HQ and OPNSense in BA. Them are connected with IPSec PB S2S VPN. There is a older solved Case for more informations:
https://community.sophos.com/sophos-xg-firewall/f/discussions/141557/need…
Good day together
I normally look after Zyxel firewalls, but I was now allowed to take over a Sophos customer from a former colleague. I would like to switch this customer from IKEv1 to IKEv2, but I don't want to make a hard switch. So that the customer…
Hi everyone,
we have an existing VPN Connection:
local subnet:
172.25.169.144/28
remote subnet:
172.25.169.104/29
no we have to translate every connection with destination 172.25.169.108 to our source ip 172.25.169.145.
i already tried…
The IPSec tunnel comes up and is seen on both ends but not able to route traffic between the two. Tried to setup static routes, no change. What do I need to set on both ends to get the traffic to flow ??
Hi all,
i have the following issue and hope that someone can give me a hint or two:
We're using a remote access connection (SSL VPN) to our Sophos XG. On the Sophos XG, we have an IPSec tunnel to another router (pfsense). Both work great.
Now, we…
Good Day,
We have four site-to-site VPNs setup and working.
Site A (Head Office)
Site B (Branch Office 1)
Site C (Branch office 2)
Site D (External party (Fortinet) site)
Site A (Head Office) connects to Site D (external party) to allows…
IPSec Site-2-Site VPN
from initiator XGS to receiver SG firewall.
the XGS is on v19.5.3
IKEv1 (caused by SG capabilities)
Whenever someone rebooted the ISP router on the XGS site, the XGS will not re-initiate the connection and sits there disconnected…
Hi,
First of all, I tried to find existing discussions about the issue i'm facing but i'm not 100% sure I've searched/used the right keywords.
Let me explain:
I have 3 sites (let's call those SS, RR and DC).
SS subnet is: 172.42.23.0/24
RR s…
Figured as since I cannot find anyone else experiencing this issue, wanted to highlight this here if it helps someone else or if Sophos want to investigate themselves. FW type, config and version in subject. TLDR: Disable HA if you experience issues with…
Dear Support, we set up a Fortigate firewall 200F at our edge and replaced the Sophos XG 210 we previously used. However, I have a remote site connected via RED devices, I decided to just continue using the RED device and move the Sophos XG behind the…
Hello, I have two sophos: - XGS107 as branchOffice (19.5.3) - XG330 as HeadOffice (19.5.2) I am experiencing strange behavior on "route-base" ipsec tunnel. Tunnel status on both sites is down but on HeadOffice i can see that connectio is UP.
HeadOffice…
Hello everyone, I have an IPsec connection to our holding with NAT, the fake local network is provided to us by the holding and can only be one. The problem is that I also have to convey other secondary networks to the tunnel, so I was thinking of doing…
We have an XGS 2100 with an IKE2 IPSEC Site-to-Site connection to Azure.
When initiating the connection, the "Flat LAN" subnet mounts but the various VLAN's bound to the "flat LAN" don't come up.
The VLAN's are used for SIP phones and WiFi access…
I spent some time on research here and I wasn't able to find something like How-To, KB artice covering this scenario where we may have Sophos LTE modem on branch office or Teltonika modem attached to port.
We do local break out for internet services…
Good day, I've been struggling with this issue here for quite some time. We have a Site-to-Site VPN setup to external company with NATed ranges. Have setup the firewall to fail-over to backup ISP should the primary ISP fail.
Trying tested it multiple…
Hi,
there is a IPSec tunnel not tunneling traffic to remote site.
Traffic from remote site to my site is sent trough tunnel as expected, but traffic to remote site is being nated and sent trough WAN interface.
Remote site has to use my internet…
Hi,
i read this post
RE: Activate and deactivate IPsec connection via CLI
It's what i need, but into Api documentation i can't see anything about this command, could you send me a documentation on info about this command?
Thanks
HI, I would need to retrieve the following information from the XG 135 Firewall via script: - VPN status node by node and child by child - restart the VPN if phase2 or phase1 is down Can you help me retrieve this information via commands? Thank you
Hello all,
We have deactivated LLMNR via GPO. After that we had the problem that users who work via VPN have more DNS problems. No problems could be found in the internal network.
In 90% of the cases, internal resources can no longer be resolved.…
Good day, Wonder if anyone can help me.
Have a site-to-site tunnel with a remote server. The remote server is connected through a site-to-site tunnel to a different company so I don't have control on the remote side network.
Now I am trying to get…
Hello,
help troubleshoot this IPSEC connection.
I have two IPSEC connections on My Sophos ( XG210 ) to AWS first is on My Primary IP which has connected successfully even though it's slow.
The Second one is on my Secondary IP which is our back…
Hello,
I have set up a site-to-site tunnel from our device XG210 to AWS, despite having less than 100ms on ping the connection is very slow, kindly advise what the issue could be the issue, since the setup is okay, and tunnels are connected.
"Good morning,
everyone. My question is the following: I have a modem that performs NAT from the public IP and provides the firewall with a private IP 192.168.1.0/24. Is it possible to establish an IPSEC connection with another firewall using a private…