• XG310v3 HA Active/Standby site-to-site VPN connections, 19.5.3. Unable to edit, delete or change status.

    Esa Salminen
    Esa Salminen
    Figured as since I cannot find anyone else experiencing this issue, wanted to highlight this here if it helps someone else or if Sophos want to investigate themselves. FW type, config and version in subject. TLDR: Disable HA if you experience issues with…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG behind Fortigate firewall

    Steven Runghen
    Steven Runghen
    Dear Support, we set up a Fortigate firewall 200F at our edge and replaced the Sophos XG 210 we previously used. However, I have a remote site connected via RED devices, I decided to just continue using the RED device and move the Sophos XG behind the…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos S2S ipsec -XGS107(branchOffice) <>XG330(HeadOffice)

    MOl
    MOl
    Hello, I have two sophos: - XGS107 as branchOffice (19.5.3) - XG330 as HeadOffice (19.5.2) I am experiencing strange behavior on "route-base" ipsec tunnel. Tunnel status on both sites is down but on HeadOffice i can see that connectio is UP. HeadOffice…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • NAT multiple networks in an Ipsec tunnel

    LMSIIATO
    LMSIIATO
    Hello everyone, I have an IPsec connection to our holding with NAT, the fake local network is provided to us by the holding and can only be one. The problem is that I also have to convey other secondary networks to the tunnel, so I was thinking of doing…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC Site-to-Site - Multiple Local Subnets

    Ryan Calvert
    Ryan Calvert
    We have an XGS 2100 with an IKE2 IPSEC Site-to-Site connection to Azure. When initiating the connection, the "Flat LAN" subnet mounts but the various VLAN's bound to the "flat LAN" don't come up. The VLAN's are used for SIP phones and WiFi access…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • dual redundant vpn tunnels from branch office to HQ office

    damiri
    damiri
    I spent some time on research here and I wasn't able to find something like How-To, KB artice covering this scenario where we may have Sophos LTE modem on branch office or Teltonika modem attached to port. We do local break out for internet services…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Route Site-to-Site VPN over different ISP

    Werner Smit
    Werner Smit
    Good day, I've been struggling with this issue here for quite some time. We have a Site-to-Site VPN setup to external company with NATed ranges. Have setup the firewall to fail-over to backup ISP should the primary ISP fail. Trying tested it multiple…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec traffic not tunneled

    Ash666
    Ash666
    Hi, there is a IPSec tunnel not tunneling traffic to remote site. Traffic from remote site to my site is sent trough tunnel as expected, but traffic to remote site is being nated and sent trough WAN interface. Remote site has to use my internet…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Activate and deactivate IPsec connection via CLI

    Davide Jadarola
    Davide Jadarola
    Hi, i read this post RE: Activate and deactivate IPsec connection via CLI It's what i need, but into Api documentation i can't see anything about this command, could you send me a documentation on info about this command? Thanks
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Check Ipsec Vpn Status by Command Cli

    Davide Jadarola
    Davide Jadarola
    HI, I would need to retrieve the following information from the XG 135 Firewall via script: - VPN status node by node and child by child - restart the VPN if phase2 or phase1 is down Can you help me retrieve this information via commands? Thank you
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • LLMNR disabled - DNS resolution no longer works over VPN

    StopTheBeat
    StopTheBeat
    Hello all, We have deactivated LLMNR via GPO. After that we had the problem that users who work via VPN have more DNS problems. No problems could be found in the internal network. In 90% of the cases, internal resources can no longer be resolved.…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • AWS Sophos IPSEC Connection _Not connecting

    IT Support236
    IT Support236
    Hello, help troubleshoot this IPSEC connection. I have two IPSEC connections on My Sophos ( XG210 ) to AWS first is on My Primary IP which has connected successfully even though it's slow. The Second one is on my Secondary IP which is our back…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • AWS- Sophos Site-to-Site IPSEC Very Slow

    IT Support236
    IT Support236
    Hello, I have set up a site-to-site tunnel from our device XG210 to AWS, despite having less than 100ms on ping the connection is very slow, kindly advise what the issue could be the issue, since the setup is okay, and tunnels are connected.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • "IPSEC with a private I

    yancarlosgarrido
    yancarlosgarrido
    "Good morning, everyone. My question is the following: I have a modem that performs NAT from the public IP and provides the firewall with a private IP 192.168.1.0/24. Is it possible to establish an IPSEC connection with another firewall using a private…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN IPsec site-to-site connexion established but no trafic

    Ricardo Ferreira Dantas
    Ricardo Ferreira Dantas
    I have a VPN IPsec tunnel between my two firewall sophos. I have a connection but no trafic. I made some firewall rules but I have nothing. This is my schema. And there are my rules: Could someone help me ? Thanks
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • DNS request to DNS over Site2Site VPN

    Christian Köhler
    Christian Köhler
    Hello! We are using a Hardware Firewall XGS-2100 to connect to two datacenters running our AD Controller there. The AD is also our DNS Server. This worked fine for a long time. For some reason one of the VPN stopped working and one of the AD Controller…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall VPN site-to-site Sophos GX and Sonicwall - dropping connection

    Geir Otto Olsen
    Geir Otto Olsen
    I have a Sophos model SFV1C4 with SFOS 19.5.2 MR-2-Build624 After the last firmware my site-to-site connections is timing out. It is Sonicwall that initiate the connections. I am using IKEv2 and after a while I get an error: ID 983 VPN IKEv2 Received…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Dead Peer Detection - Design Flaw and workaround

    Steve Klassen
    Steve Klassen
    Dead Peer Detection has a hidden design flaw. Dead Peer Detection is a feature designed to retry\re-establish a tunnel when a tunnel drops. You can set 3 settings in this feature for 1)how long to wait before a retry, 2)how long to wait for a response…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG fail with issue "IPsec connection could not be established" with Tunnel interface AWS.

    System Admin12
    System Admin12
    Dear Support; I am using sophos xg firewall hardware device. I do IPSec configuration with AWS according to their configuration file. And follow Sophos Firewall: AWS VPN Gateway IPSEC Connection I received the notice "IPsec connection could not be…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • V19.5.3 and HA-Cluster - VPN Fails "invalid SPI" after upgrading

    juergenb52
    juergenb52
    Hi, i upgraded our XGS2100 from 19.5.2 to 19.5.3 We had a solid VPN Connection to a customer, after upgrading the Connection fails from time to time and VPN Log shows. 2023-08-28 10:11:14 IPSec Deny Received IKE message with invalid SPI (19CBD566…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site-to-site VPN - Why can't you view your settings when you have a failover group

    Steve Klassen
    Steve Klassen
    Why can't you view your site-to-site settings when you have a failover group active. Whenever I'm working with a SOPHOS engineer on an issue, the first thing they want to do is view the VPN settings, but they can't without taking the VPN tunnel offline…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC VPN traffic not passing passing through to DST IP

    RyanHosiassohn
    RyanHosiassohn
    Hey All, , So i had something interesting that got fixed today. On the old XG V17-19 when you create a IPSEC VPN, you didnt need to add a no NAT rule (I could be mistaken if some one can confirm this) But on the XGS, I had setup all the VPNs…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Ipsec site to site connection

    mulah
    mulah
    im having the problem with ipsec to a client with cisco firewall. The firewall cannot connect to the remote site but the policies and the satting are the same. This is how my setup is Local Public ip : 154.120.225.2 Local ID : set as the Public ip…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Need Help with Client IPSec VPN (Connect) in to Site2Site VPN IPSec Tunnel (Policy Based)

    David Lorenz
    David Lorenz
    Dear Community, my name is david lorenz and I have a problem at one of our customers. At first I will describe my network situation. They have a HQ and a BO. The HQ has the network: 192.168.2.0/24 (Sophos XG210 with 192.168.2.1) The BO has the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall Drop several initial packet from vpn site to site

    Tri Nguyen2
    Tri Nguyen2
    I have configured an IPSec VPN site-to-site connection between two sites, and after that, the ping traffic was going through between the sites. However, about 10 minutes later, when I pinged again to check, there were always a few initial packets that…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>