• IPSEC Setup with Zscaler

    v h
    v h
    hi all, we encountered some limitation with sophos fw, under SFOS 19.5 with IPSEC configuration. There is no possibility to set null encryption under ipsec phase 2 part. Is there a way to bypass this limitation ?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec site-to-site vpn problem with dnat servers

    Kevin Stepper
    Kevin Stepper
    Hi, we have an XG135 in the headoffice and an XG87 in the branch office. in the headoffice we have two servers ( mail and something else ) that need to be reachable from the outside and we used the Server Accesss Assistant to create the correpsonding…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos SG --> XGS IPSec Connection Terminated

    admin_idl
    admin_idl
    hi, we have the problem that an IPSec connection between SG and XGS shows Terminated status several times a day and then the status changes directly back to established and the connection continues to work without problems. What settings or logs should…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN IPSEC Site-to-site service times out in IKE phase until reboot

    Camemiya
    Camemiya
    Hello, We have the following scenario: Two Sophos XG310 with active-passive high availability enabled. Since we configure high availability from time to time, the site-to-site ipsec VPN service just stops working, 80% of our tunnels are disconnected…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Can't access or ping IPSec Site-to-Site Local to Remote devices

    bcharles
    bcharles
    Hi, I'm trying to enable an IPSec Site-to-Site connection with a remote location but have a few problems on the route side Here's my config : Sophos XG - SFOS 19.5.2 MR-2-Build624 Sophos LAN on 172.16.16.x (set as LAN in Hosts and services)…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Need to re-input the Pre-shared key to establish Sophos to FortiGate

    sndyblz
    sndyblz
    We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script. The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SOPHOS Purposefully Designs bugs into their Firewalls: Episode 2 – Email Alerts, Green Statuses, and Routes

    Steve Klassen
    Steve Klassen
    I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into. Episode #1 community.sophos.com/.../sophos-purposefully-designs-bugs-into-their-firewalls-episode-1---vpn-failover-and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SOPHOS Purposefully Designs bugs into their Firewalls: Episode 1 - VPN Failover and WAN Interfaces

    Steve Klassen
    Steve Klassen
    I’m documenting my numerous issues with SOPHOS Firewalls so that others can be aware of what they are getting themselves into. Our Background: My business is a long time customer of SOPHOS Firewalls(more than 10 years). We have 18 Firewalls and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ESET endpoint failing to activate

    Anesu Dangarembwa
    Anesu Dangarembwa
    We have a Sophos firewall xgs 2300 v19.00, the firewall is configured VPN to branches, machine at the branch office are failing to activate ESET endpoint.. at the head office we have a ESET server
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Odd Behavior with System Generated Traffic over IPSEC

    Corey-FTK
    Corey-FTK
    Hi, Encountering a weird error when trying to attempt using a server for DNS forwarding. We have a few branch offices - each connecting to DC via IPSEC (Connection Type: Site-to-Site / IKEv2) - with the DNS Forwadering Host in the DC. Now here's…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ipsec

    satyabrata bastia
    satyabrata bastia
    Hi, we are using sophos xg firewall we need to create one tunnel between two site both side sophos xg firewall. head office having all server and ad and dc server also. so all user are in branch office access server head office and all internet traffic…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • UNABLE TO ACCESS SERVERS IN HQ LAN FROM BRANCH OFFICE

    Tarisai Dhombo
    Tarisai Dhombo
    I am able to ping My my gateway from HQ which is my XG Firewall LAN interface ,but i am unable to ping anything in the LAN ,from Branch Router to HQ Router i have a GRE Tunnel,What do i need so that i am able to access LAN resources in Branch
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec traffic no longer in VPN Zone?

    Thorben Paulik
    Thorben Paulik
    Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using: Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Couldnt parse IKE message

    PeteH
    PeteH
    Can anyone tell me how i can stop this from happening? The IP address is from Ukraine and nothing to do with this connection or s2s so I am a bit worried its some sort of attempted hack on port 500. Ive put a block (drop) on the IP incoming but thats…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • OSPF over IPSec to FortiGate firewall

    Steve Deviller
    Steve Deviller
    Hello All, We have a site that has a FortiGate firewall at the main site and several old watchguard firewalls at remote site. We need to replace one on the firewalls at a remote site, hoping to replace all later, with a new XGS3100. Due to the current…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPsec connection attempt

    BAD
    BAD
    Hi to all, I have a lot of connections attempts for the IPsec service: Always from the same two or three IPs. Is there any way to block all for IPsec except the remote IP of the tunnel? Thanks in advance. Best regards.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC Sophos XG 18.5 (Nat configuration from tunnel)

    Boune
    Boune
    Hello, I got a IPSEC VPN from my sophos xg to remote firewall. Many subnet from my side are nated dynamiclaly with 172.30.10.0/24 to reach different subnet on the other side. Like (192.168.1.0/24 , 192.168.2.0/24 ...are nated with 172.30.10.0/24…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG v19.5.2 ipsec VPN routing problems

    MarkThornton
    MarkThornton
    I am having difficulty routing across our vpn's. I need for Host1 and Hostt2 to be able to reach Alert11, Alert12, and Alert13 but currently that isn't happening. I can reach Gateway11, Gateway12 and Gateway13. The network looks like this: NetworkA…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • aws site to site

    Ricardo Madrid
    Ricardo Madrid
    I have site-to-site connection from office to AWS VPC 1 another one from office to AWS VPC 2, using a firewall XG230 in office, what can be done to create a communication between AWS VPC1 and 2.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Vpn IPsec issue

    Arch Capital
    Arch Capital
    We have issue with IPsec configuration we create branch and headquarter vpn but not connect all setting is ok The main firewall is fiber connection The branch firewall is 5G router connection Reply to chat and email / turky@thearchcapital.com
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site IPSec Not Working As Intended

    haydenspence
    haydenspence
    Hi. I am currently working with a test environment and have configured two XG firewalls to have an IPSec Policy-based site-to-site connection between them. I cannot get the IPSec connection to forward traffic correctly. I have been trying for hours…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 210 IPSEC DOWN FAILED PARSING IKE

    Simon BALAND
    Simon BALAND
    Hi, We are losing our ipsec link after some time. (randomly) Initial connection is ok no problem But in logs we have this message : IPSEC FAILED Couldn't parse IKE message from : X.X.X.X Check the debugs logs ID 18052 If i reinitiate manually…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Internet traffic not routed from branch office through head office via site-to-site VPN

    brucepott
    brucepott
    Hi, we have a head office XG135 and 4 branch offices connected with site-to-site vpns and various sophos firewalls. ( 125, 87,86 ) VPNs are working fine. We want to route all internt traffic from the branch offices through the headoffice internet…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec to Azure - Tunnel interface missing after creation

    Matthew Wall
    Matthew Wall
    Hi all, I have been having an issue with my XG330 firewall. I created a Tunnel Interface to Azure, and see that the IPSec tunnel is not appearing under my network interfaces. I have followed the documentation highlighted here. Sophos Firewall: Configuring…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos to Fortigate site to site issue

    sndyblz
    sndyblz
    Anyone has a experience on create a site to ste vpn with fortigate firewall (as spokes and Sophos as hub), and face the ff issue: Random instances the spoke site went down even the isp has stable connection. And every time one or 2 sites (spoke, we…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>