• Assistance Required with Site-to-Site VPN Configuration between sophos and Azure

    Michael9609
    Michael9609
    Dear Sophos Support, I hope this message finds you well. We are experiencing an issue with our Site-to-Site VPN setup. While the VPN tunnel appears to be up and stable, we are unable to access the servers that are sitting behind the Azure gateway…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Ipsec VPN couldn't established.

    Dinesh Kandeeban
    Dinesh Kandeeban
    Hi, I have configured the tunnel from DC to another location, The tunnel couldn't established. I don't know what is the reason the tunnel has down. I have debug the issue still unable to find out the issue, please assist me to resolve the issue
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Sophos VPN

    Yasha Burns
    Yasha Burns
    Hello, Recently one of our clients contacted us about purchasing some new Sophos firewalls. They had some VPN settings on their old Meraki firewalls. We have the VPN settings now, but it seems like most of these settings don't even exist in the Sophos…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Sophos site to site VPN changes take long to apply, changes dont apply

    Rog163
    Rog163
    Hi All - ive had this issue for over 2-3 years now - when trying to make changes on site to site vpns - either the changes take long to apply, dont apply or need to apply several times. i try to change local ID for example on an existing site to site…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • VPN with Drayteks constant disconnects

    Andrej Pirman
    Andrej Pirman
    Hi, I have a bunch of XGS firewalls in main offices of my customers, which have branch/remote offices with Draytek routers, different models. I have not paid attention till now, when one of those reported intermittent issues with Site2Site IPSec VPN…
    • Answered
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • No traffic through VPN tunnel

    b_trahn User
    b_trahn User
    Hello, I have a problem with an ipsec Site to Site tunnel. The tunnel is being built, but no traffic is going through the tunnel. The remote station is connected to a router via LTE and a Dyn DNS entry. I checked local and remote subnets. The firewall…
    • Answered
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • NAT between RED20 and IPSec on XGS v20

    Heiko Dammlaks
    Heiko Dammlaks
    Hi I need to translate packets between an ISec and a RED 20. There is an IPSec tunnel with 172.18.10.0/24 on the remote site and 172.26.143.1/24 on the Sophos. I have a RED device with 192.168.54.1/24. I would access form REDs subnets hosts (maybe…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • NAT over IPSeC Site-to-Site VPN

    Dimitris Roubos
    Dimitris Roubos
    Greetings fellow members, I have 2 networks with 1 sophos firewall each, network A (Public IP/80.80.80.128, Local Network/192.168.20.1/24) and network B (Local Network 192.168.10.1/24). Sophos B XGS107 ( SFOS 19.5.3 MR-3-Build652) Sophos A XG135…
    • Answered
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • HOW TO CHECK FOR UP TIME IN IPSEC VPN TUNNEL

    eFrancis
    eFrancis
    Hello All, The client has requested to know the uptime in the IPSEC VPN Tunnel. Sophos Model: XGS4500 Thank you
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • XGS87 (SFOS 20.0.2 MR-2-Build378) VPN Routing Problem

    Help Me
    Help Me
    Hello, we have a problem which with the routing over VPN. A user is connected to SSL VPN with the XGS. The XGS has a site to site IPsec VPN connection to resources in the cloud. A request from the user's client using SSL VPN for resources in the…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • IPSEC connection showing this error Couldn't authenticate the local gateway. Check the authentication settings on both devices.

    Anesu Dangarembwa
    Anesu Dangarembwa
    We are trying to setup a IPSEC tunnel between a Sophos Firewall and a ISR4300 After activating its showing error Couldn't authenticate the local gateway. Check the authentication settings on both devices.
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • WIFI "separate zone" didn't work over IPSec

    dirkkotte
    dirkkotte
    Hi all, AP configuration works. I am able to remove & add the AP's. AP's are recognized and shown as active. I can see the traffic between AP & XGS Port 2712. Traffic to port 8472 from firewall to AP is not answered, but i see packets from AP to APIPA…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Firewall IPsec Site2Site settings page slowdown

    Jens Frankiewicz
    Jens Frankiewicz
    Hi all, when we try to add or change a configuration on the IPsec settings page on our XG/XGS Firewalls we always have to wait for about 2 minutes for the site to load and for it to be usable. The web browser shows the message "This page is slowing…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Disconnection Ipsec with fritz

    Lorena Zandona
    Lorena Zandona
    After update to my xg firewall to v20 ipsec is become unstable. Randomly disconnection. openvpn client work without issue only ipsec have problem Some info: this setup worked for 2 year without a problem (another bug on v19 but fixed). Sophos firewall…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • IKEv1 PSK with same Gateways

    Quallensaft
    Quallensaft
    Hello @all, it is known that with IKEv1 on SFOS a new PSK overwrites all others PSKs if the gateways do not differ in the connections. Sadly I can not use IKEv2. Is it sufficient if just the local ID is different in connections and the remote ID is ANY…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • IPSEC down/up e-mail notification every 30 minutes

    Christian Garcia N
    Christian Garcia N
    Good morning. I have several XG/XGS of different clients configured with IPSEC against the same central, this central uses a CISCO firewall (we do not manage it). The problem we have is that every 30 minutes we receive an email from all the XG/XGS indicating…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Multiple Gateways in Branch Office

    CreateShare
    CreateShare
    Hi, What is the proper way to connect a branch having multiple internet gateways but the head office has only one gateway? The branch office WAN1 interface has a Real IP but WAN2 uses DDNS with a dynamic IP. Should the branch office have a failover…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Yellow Icon under IPSec Status

    CreateShare
    CreateShare
    Hi, One of my IPsec tunnels shows a yellow icon under the status but when I click on the connection details, all subnet connections show green. Any Suggestions?
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site VPNs and VLANS

    Randy Cleveland
    Randy Cleveland
    Hi, We've run a flat lan for years at our main location. We've recently updated our network and added a few new VLANS to the mix. Now I have a problem. We have several Site-to-Site VPNs up and running that work great with our original VLAN1. However…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPSec site to site vpn, one tunnel goes down frequently

    Lennart Johansson
    Lennart Johansson
    Hi, I have a Sophos XGS107 (SFOS 20.0.1 MR-1-Build342) setup with Site to Site vpn to a Mikrotik router. There is 4 vpn tunnels (or separate address pairs), It mostly works fine, but every other day one tunnel goes down. If I check in webgui >> site…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • SD WAN config between CGW and AWS EC2 Virtual FW

    Matt Carter
    Matt Carter
    Hi all, we currently have 20 sites all using Sophos XG107 or XG 117 FW. all sites have a S2S VPN connection into AWS for SMB access. issue we have is failover internet, if failover is required then our VPN drops due to new IP. Failover internet is…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPSec Recommended Settings for Branch Office

    CreateShare
    CreateShare
    Hi, Are there any specific IPSec Profile recommendations for connecting the branch office that does not have a static real IP Address? I am currently using the DefaultBranchOffice profile, but it disconnects automatically after some time. Thanks.
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Add subnets to NAT with policy-based IPsec when local and remote subnets are the same

    Mark Tarrant
    Mark Tarrant
    Hello all, I have a situation with a IPsec VPN setup between two sites that have subnets that are the same. I followed these instructions and it worked ok; NAT with route-based IPsec when local and remote subnets are the same - Sophos Firewall However…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Site to site VPN to a vendor site with the same subnet at both ends

    Mark Tarrant
    Mark Tarrant
    Hello all, we are looking at a situation where we need to set up a site to site VPN to a vendor who is using a Fortigate gateway, and the same subnet is being used at both ends. I have reviewed the below link which covers this situation for Sophos to…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • XFRM showing 'not configured' after public IP changes on spoke

    GJN
    GJN
    Hello, we are currently using Sophos Firewalls in a Hub-and-Spoke topology running SFOS 20.0. Some spokes are using WAN connections with dynamic IPs which will change from time to time. On those units we can observe that the corresponding XFRM interface…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>