• IPSec Site to Site VPN Disconnection

    Jason G
    Jason G
    Hello, I have setup a site to site IPsec VPN between a Sophos XG (Responder) & a DrayTek (Initiator) router. Everything is working as it should apart from a disconnection every so often. I believe this has something to do with the re-key event that…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Crear enrutamiento entre dos VPN

    Lluis Bigordà
    Lluis Bigordà
    Buenas, necesito ayuda, porque no consigo por mis medios.. La SubredLocal la llamaremos Subred1 Tengo un Sophos XG, que esta conectado a otro host a través de una IPsec "Interfaz de Tunel", la llamaremos Subred2. Luego tengo usuarios que se conectan…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site to Site VPN

    sherwin ramos
    sherwin ramos
    Greetings, We've set up a Site to Site VPN in our Main and branch office, they were active but we're still unable to ping the ip address from the main. Can anybody help me with this?? or any configurations i need to check please? thank you.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec connection is Down after migrating systems to another data center (WAN IP changed)

    cap admin
    cap admin
    The information provided by clients is as below From our admin side, we already amended the information such as local subnet and remote subnet as below except the interface wan1 Do we need to match the interface also? We do not know how…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN TELTONIKA RUT240 and SOPHOS XGS

    Edvvde
    Edvvde
    Hello everyone, I have successfully established an IPSec site-to-site connection between a SOPHOS XGS firewall and a RUT240 from Teltonika. A ping from the Teltonika router to the SOPHOS firewall works. A ping to an end device behind the SOPHOS firewall…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC-SITE-TO_SITE (Unable to resolve %any)

    Verdigo
    Verdigo
    I'm having issue with my IPSEC-site-to-site connection. The IPSEC vpn cannot be established. Im having error " unable to resolve %any, retrying in 60s" when checking the strongswan.log Here is the full logs: loading secrets from '/_conf/ipsec/ipsec…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Destination Unreachable

    SATHEESH KOOLIPPILAKKAL
    SATHEESH KOOLIPPILAKKAL
    I have setup IP-Sec between head office and branch office few days back. My branch office is working perfectly fine and accessing all the resources on the head office but on the other hand when i try to access or ping any resource on branch office from…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Full tunnel site to site IPsec VPN bug

    Shunze Lee
    Shunze Lee
    Hi All, We have a question in Full tunnel site to site IPsec VPN. When we create a local 192.168.183.50/32 to remote Any site to site IPsec VPN. We found that XG's own routing will also be carried out through this VPN tunnel. There…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Routing between 2 Branch Offices

    Koumni Moussa
    Koumni Moussa
    Hello, I have 2 branch offices that are connected to the head office via VPN , now I want to connect these 2 offices to each other using the head office as a forward node, is that possible? if so please explain how PS: The branch offices don't have…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • About Ipsec site-to-site connectivity

    ab awal
    ab awal
    I am using XGS136 Firewall, Recently I restored a backup to XGS136 from XG 126. Now I fell to an issue that my ipsec site-to-site connectivity does not work properly, though the connectivity status is green. like site A user access site B, but site B…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN IPsec status of connection - monitoring via API/SNMP

    Roman Tucek
    Roman Tucek
    Hello, I would like ask , if somebody know , if will be option monitor VPN IPsec via snmp or API. I found , that is offen question in the forum. Sophos XG - SNMP - Monitor tunnel status Check Ipsec Vpn Status by Command Cli Read IPSec Connection…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to configure an IPsec VPN failover with 2 gateways on each end

    Lais Medeiros
    Lais Medeiros
    Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot. I thought about doing it like this: The Branch initiates…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Recommendations for Site2Site TunnelAll VPN

    kerobra
    kerobra
    We will have a special deployment at one customer soon. The customer has serveral branch offices where Sophos XGS 136 will be the local gateway for 5-6 subnets for each branch office. The BO firewalls will only have base subscriptions and only some…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • GRE tunnel local gateway config error

    Takashi Miyazawa
    Takashi Miyazawa
    Hi all, I got the following error when I tried to configure GRE tunnel on my Sophos FW (v19.5, home). console> system gre tunnel add name GRE1 local-gw Port1 % Error: Unknown Parameter 'Port1' The WAN port I am trying to configure GRE is Port1,…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec S2S Policy Based VPN (btw. XG and OPNSense) - Routing Problems

    David Lorenz
    David Lorenz
    Dear Community, we have a customer with a XG Firewall in HQ and OPNSense in BA. Them are connected with IPSec PB S2S VPN. There is a older solved Case for more informations: https://community.sophos.com/sophos-xg-firewall/f/discussions/141557/need…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Two IKE VPN configurations on one firewall

    Niklas R
    Niklas R
    Good day together I normally look after Zyxel firewalls, but I was now allowed to take over a Sophos customer from a former colleague. I would like to switch this customer from IKEv1 to IKEv2, but I don't want to make a hard switch. So that the customer…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Relay traffic from branch office site-to-site to remote site through head office

    Werner Smit
    Werner Smit
    Good Day, We have four site-to-site VPNs setup and working. Site A (Head Office) Site B (Branch Office 1) Site C (Branch office 2) Site D (External party (Fortinet) site) Site A (Head Office) connects to Site D (external party) to allows…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS to SG UTM IPSec VPN not reconnecting, staying in disconnected state forever (IKEv1)

    LHerzog
    LHerzog
    IPSec Site-2-Site VPN from initiator XGS to receiver SG firewall. the XGS is on v19.5.3 IKEv1 (caused by SG capabilities) Whenever someone rebooted the ISP router on the XGS site, the XGS will not re-initiate the connection and sits there disconnected…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Hide NAT

    Bischof IT Support
    Bischof IT Support
    Hi everyone, we have an existing VPN Connection: local subnet: 172.25.169.144/28 remote subnet: 172.25.169.104/29 no we have to translate every connection with destination 172.25.169.108 to our source ip 172.25.169.145. i already tried…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Routing through an IPSec VPN

    Thomasb74
    Thomasb74
    Hi, First of all, I tried to find existing discussions about the issue i'm facing but i'm not 100% sure I've searched/used the right keywords. Let me explain: I have 3 sites (let's call those SS, RR and DC). SS subnet is: 172.42.23.0/24 RR s…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site to Site XGS-126 to UniFi USG-Pro-4 not routing

    Michael Witmer
    Michael Witmer
    The IPSec tunnel comes up and is seen on both ends but not able to route traffic between the two. Tried to setup static routes, no change. What do I need to set on both ends to get the traffic to flow ??
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG310v3 HA Active/Standby site-to-site VPN connections, 19.5.3. Unable to edit, delete or change status.

    Esa Salminen
    Esa Salminen
    Figured as since I cannot find anyone else experiencing this issue, wanted to highlight this here if it helps someone else or if Sophos want to investigate themselves. FW type, config and version in subject. TLDR: Disable HA if you experience issues with…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG behind Fortigate firewall

    Steven Runghen
    Steven Runghen
    Dear Support, we set up a Fortigate firewall 200F at our edge and replaced the Sophos XG 210 we previously used. However, I have a remote site connected via RED devices, I decided to just continue using the RED device and move the Sophos XG behind the…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos S2S ipsec -XGS107(branchOffice) <>XG330(HeadOffice)

    MOl
    MOl
    Hello, I have two sophos: - XGS107 as branchOffice (19.5.3) - XG330 as HeadOffice (19.5.2) I am experiencing strange behavior on "route-base" ipsec tunnel. Tunnel status on both sites is down but on HeadOffice i can see that connectio is UP. HeadOffice…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • NAT multiple networks in an Ipsec tunnel

    LMSIIATO
    LMSIIATO
    Hello everyone, I have an IPsec connection to our holding with NAT, the fake local network is provided to us by the holding and can only be one. The problem is that I also have to convey other secondary networks to the tunnel, so I was thinking of doing…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>