This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't get XG 115 SSL VPN to pass traffic

Okay, 

I've joined this forum because I'm now 8+ hours into trying to get basic SSL client VPN services working to a new (and very expensive) XG115 that I've recently installed on a small network.

When I first started setting this up I observed that a how-to guide had been recently authored and thought "great, this will make things easy!".  Wrong.

If I can't get this sorted this expensive XG is going to be on its way back to the vendor I got it from.

The guide is here;

https://community.sophos.com/kb/en-us/122769

I was able to follow everything indicated with one exception, in the "tunnel access" of the how-to it indicates you should be able to select an IP group you previously created, but on my XG (FW SFOS 17.0.8 MR-8) I don't get this option, I only get the option to choose the physical interfaces and VLANs administered on the Firewall.

I am able to download the configuration and get the tunnel established.  The firewall rules show no traffic passing through (0 bytes sent 0 bytes received).  If I status the user in current activities I see my user connected and it even shows a small amount of upload traffic, but the client can't ping anything or access anything on the LAN side of the network.

After spending multiple hours trying to get something so basic to work I started digging for anything else that might help;

I looked at this post https://community.sophos.com/products/xg-firewall/f/vpn/93396/can-t-get-ssl-vpn-to-pass-traffic and then this one community.sophos.com/.../ssl-vpn---can-connect-but-no-traffic

which included a bewildering array of advice including that a FW rule was needed in the LAN to VPN direction (this is not indicated in the How-To article), that MASQ NAT should be enabled, that in the VPN policy "use as default gateway" must be turned on, etc.

I have tried all of this stuff and it still does not work.  The Firewall logs don't even show it filtering any traffic through the VPN rule.  I have re-downloaded the configuration each time I've made a change (stupid btw) and tried connecting on multiple computers and operating systems.

This was supposed to be up and running a week ago and I've never had so many problems getting basic client access working with a UTM.  Can someone help me please? To make matters worse there is nobody technical at the site so every time I need to work on this I am driving across town and sitting there trying to troubleshoot this thing for hours.  The business owner simply needs to be able to VPN into the site from their PC when they are away and access machines via remote desktop.  Should be easy, done it many times with other products, apparently in Sophos XG land nothing is easy.



This thread was automatically locked due to age.
  • IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination        Netmask          Gateway       Interface  Metric
              0.0.0.0          0.0.0.0      172.20.10.1      172.20.10.3     50
          10.81.234.0    255.255.255.0         On-link       10.81.234.6    291
          10.81.234.6  255.255.255.255         On-link       10.81.234.6    291
        10.81.234.255  255.255.255.255         On-link       10.81.234.6    291
            127.0.0.0        255.0.0.0         On-link         127.0.0.1    331
            127.0.0.1  255.255.255.255         On-link         127.0.0.1    331
      127.255.255.255  255.255.255.255         On-link         127.0.0.1    331
          172.20.10.0  255.255.255.240         On-link       172.20.10.3    306
          172.20.10.3  255.255.255.255         On-link       172.20.10.3    306
         172.20.10.15  255.255.255.255         On-link       172.20.10.3    306
          173.14.9.65  255.255.255.255      172.20.10.1      172.20.10.3    306
         192.168.10.0    255.255.255.0      10.81.234.5      10.81.234.6    291
            224.0.0.0        240.0.0.0         On-link         127.0.0.1    331
            224.0.0.0        240.0.0.0         On-link       172.20.10.3    306
            224.0.0.0        240.0.0.0         On-link       10.81.234.6    291
      255.255.255.255  255.255.255.255         On-link         127.0.0.1    331
      255.255.255.255  255.255.255.255         On-link       172.20.10.3    306
      255.255.255.255  255.255.255.255         On-link       10.81.234.6    291
    ===========================================================================
    Persistent Routes:

  • Can you show me the current policy and interfaces of XG? 

  • I removed and re-configured a couple of things that I had previously configured and now it is working.

     

    Definitely the trip-up here is around needing to define the target IP range and expressly adding it to the VPN profile.

    I will provide some feedback on the current (just published July 6) rule that doesn't explain this adequately.

    I do have one lingering question.... how can I access the Sophos management interface itself over the VPN connection?  I would assume it should work but it does not.

     

    Thanks... especially to ManBearPig who seems to have had the answer on this one.

  • Hello,

     

    You could access the Sophos Manager interface from VPN by checking the same tick that in this screenshot : 

    it's in the "administration > device access" tab.

  • Correct and access the Gateway / Interface Port of XG.

    Or connect via WAN Interface. Its a https tunnel. So basically also possible.