• HTML5 VPN Web Portal

    Hi I have a webserver running here and I can reach with the HTML 5 VPN Portal. It shows it's openend in IE but it seems to open a Firefox session inside it. When I try to open a pop-up, it says it's being blocked by "nightly". I looked this up and it…
  • Webadmin+VPN problem in China

    Hello I've setup a Sophos SG135 for our office in Shanghai 2 years ago. I'm based in France and I've mounted an IPSEC VPN between our SG310 in Paris to the one Shanghai back then. It's been working just fine for 2 years but approx 3-4 weeks ago…
  • Sending Remote access traffic through Site-to-site VPN, with 1:1 nat translation

    Hi, I have searched for an answer to this, but am unable to find a result which includes a 1:1 NAT. Here is the scenario: Remote User -(SSL Remote Access VPN)-> Sophos UTM 9 -(IPSEC Site-to-site VPN)-> Partner servers We have a requirement for…
  • SSL VPN not working

    Hi! I can't get my SSL-VPN to work, I followed Sophos own guide for setting this up, only changing the port. See below for settings. The log outputs the following: 2017:11:10-14:47:05 openvpn[25581]: TCP connection established with [AF_INET…
  • Can the Sophos IPSec client and Sophos UTM SSL client be installed on the same computer?

    Is there any problem with installing the Sophos IPSec client (11.x) and the Sophos UTM SSL VPN client on the same computer? Is there any conflict between the two clients? Only plan to make a connection with one client at a time. I just wanted to know…
  • Granular access for SSL VPN remote access

    Hello fellow forum users, I have currently set up a SSL VPN remote access in Sophos UTM9 and its working without any issues, i can access all the services on all ports in the local network without issues. The problem is i want to restrict…
  • UTM v 9.503-4 certificate problem

    Hello, got message from UTM: 1 certificate(s) will expire within the next 30 days: Proxy CA when I clicked Regenerate button, next day - no SSL VPN client could connect, so I restored backup... but I do have problem: some users have certificate…
  • IPSEC VPN from UTM 9 to a Cradlepoint

    Hello, I've setup a few IPSEC VPN's with customers and vendors in the past without issue. For a proof of concept I'm attempting to create a VPN with a Cradlepoint device. Nothing special being done in regard to the config but I cannot get the tunnel…
  • Site to Site VPN : RED

    Hello, I still don't get it, what are the purpose to use a RED site to site VPN ? From what I read: - its slower than IPsec. - its as easy as SSL VPN to setup. - its not possible to extend a same subnet with this mode because you have to…
  • No WebAdmin access over VPN using public hostname

    I can't access the WebAdmin despite being connected via VPN (SSL). Here's the basic configuration: The UTM has a publicly accessible hostname (with matching certificate) - COMPANY.COM -> our public IP On our internal DNS it also has a local DNS entry…
  • Unable to connect to local resources on VPN connected machine

    Our users are able to connect to the VPN successfully and connect to network shares and all resources. They can even connect to the local C:\ drive of a user in the office however if a user connected to our LAN tries to connect to the local C:\ drive…
  • L2TP IPSEC Clients can connect to the internal network but not to the internet

    Hey everyone, I thoroughly followed the guide https://www.sophos.com/en-us/medialibrary/PDFs/documentation/utm90_Remote_Access_Via_L2TP_geng.pdf with my test setup of a SOPHOS UTM 9 essentials firewall edition. I managed to get my client connecting…
  • IPSec-VPN with NAT

    Hi all, I just created a new Site-to-Site-VPN with IPSec and the VPN is UP. If I log into my Firewall and try to ping the private IP on the other party, it works, if I try to do that from my PC it does NOT work... The VPN should use two private…
  • VPN SSL emailprotection

    Hallo, Ich nutze eine UTM. Diese sichert den Emailverkehr eingehend und ausgehend ab. Intern nutze ich keinem Emailserver sondern die Clients greifen direkt über den Pop3 Proxy auf die externen Emailserver zu. Im internen Netzwerk funktioniert dies…
  • Can you keep the same IP when remoting into network?

    OK, so we have some software on the network that licences users by IP address. When a laptop is taken out of the office and uses a remote connection to dial in (either by using a RED or by Sophos SSL VPN client) they are obviously assigned a different…
  • WebProtection: Routing to Internal Networks when "Optional: Interface for Outgoing traffic" is used

    Hello, we have the following Problem: We use the option "Optional: Interface for Outgoing traffic" for our WebProtection Profiles, so different customers can browse websites with different public IPs. If we want to connect to an internal web-server…
  • Open VPN - Too many open files

    Hi, We have UTM 9 (9.501-5) deployed in AWS for VPN purposes and it was working fine for about 1 year, but since a few weeks now we're having major problems. Every day the VPN becomes unresponsive and in the openvpn.log files we see thousands of lines…
  • Remote SSL VPN Users cant reach port 4443/4444 on their browser

    Some Remote VPN users cant reach Admin Page and User Portal on both 4444/4443 respectively but pings and telnet work on those ports from the same system. Could it be public IP related problem?
  • When (if ever) will UTM support IKEv2?

    Hi all, We use Sophos UTM V9 for a lot of things and have always been very pleased with the quality and supported features. In the past, we also used Sophos UTM for a site to site IPSEC-VPN tunnel to a virtual network on Microsoft Azure. Not anymore…
  • Remote Access IPSec VPN disconnects

    Our Remote Access IPSec VPN is disconnecting when the IKE SA lifetime is met. The IPSec policy is set to defaults (with strict policy checked) IKE SA lifetime – 7800 IPsec SA lifetime - 3600 Sophos IPSec Client log: 9/15/2017 8:21:04 PM - ERROR…
  • Site-to-Site VPN, UTM to SonicWall, Connection made but no traffic

    Welcome to my nightmare. On-site UTM, remote office SonicWall. Before turning on VPN for the entire remote network, I tried to set up just a single host on the same LAN which navigates IPSec phase 1&2 successfully. The connection is up, but no traffic…
  • Client can't access the server via ipsec vpn even though ipsec is connected.

    Hello, I have an issue related to ipsec. Definitely IPSec was not disconnected, but client which was located in BO can't access the server which was located in HO via IPSEC tunnel. PING reached a destination server correctly when client was not able…
  • IPsec route over gateway route

    Hi all, I want to know how does the Sophos UTM take priority on network routing. Take the snapshot below as an example. This routing table is taken from the Sophos UTM at Support > advanced > Routing Table default via <ISP gateway> dev eth1 table…
  • Unable to block Psiphon traffic - miscategorized as "Unauthorized Hotspot Client"

    We have a number of users that are using Psiphon to bypass our web filter and Wifi voucher system. Although the UTM has an application profile for Psiphon, it doesn't appear to work properly. For the locations that I know are using Psiphon, there is no…
  • One seperate external Line for only one SSL VPN Power-User of many

    Hello Everyone, a customer of ours asked us a question about giving a Power-User a seperate DSL-Line with a static IP-Address for his home-office. So here is my question: Is it possible to give one single user an ssl-vpn profile that connects…