This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to site VPN won't go online

Hi,

I'm currently facing a problem setting up a site to site VPN. It worked with our Sonicwall NSA 2400. With the new XG210-HA it doesn't go online.

Unfortunately the settings were changed as the old settings weren't secure enough after 6 years, so everything was set up from scratch.

Our XG connects to a UTM. We use IKEv2 and MainMode. AES256 with SHA512 and Group 16 MODP 4096 in phase 1. Same for phase 2. Encryption is done by RSA key. Settings on both sides have been double-checked.

 

All I ever see is

 

Any ideas? Thanks.



This thread was automatically locked due to age.
Parents
  • Jelle,

    you need to switch to IKE v1 because UTM does not support IKE v2. You can also use RED site to site with UTM:

    https://community.sophos.com/kb/en-us/125101

    Regards

  • OK, switched to IKEv1. Now I get

    "received IKE message with invalid SPI (E6AA7B1) from other side"

    Also tried 96bit truncation but that didn't change anything.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • I also get

    parsing IKE message from xxx.xxx.xxx.xxx[500] failed

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

Reply
  • I also get

    parsing IKE message from xxx.xxx.xxx.xxx[500] failed

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

Children
No Data