This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect vs DNS

So i finished all the instructions as posted on page https://community.sophos.com/kb/en-us/133109

Downloaded the client and exported the configuration. Set up the client and finally made a connection.

So far so good. Can ping hosts on the internal network by ip adress, however i can't seem to reach hosts by their name.

I did enter the ip of the DNS server but somehow hosts aren't being resolved.

 

Any thoughts or pointers on this.

 

Thnx, Peter-Paul



This thread was automatically locked due to age.
  • Thnx! Just downloaded and installed Sophos Connect 1.3

    Now I need to set up UTM:

    1. setup the VPN

    2. export the connection for the client.

     

    I've done this on the XG FW but can't seem to find the settings in UTM. Any help will be appreciated so i can continue my testing.

     

    Grtz, Peter-Paul

  • Hello Peter-Paul,

     

    Setting up UTM policy for Sophos Connect is very easy. Here are the steps.

    1) Go to Remote Access->IPsec page

    2) Add a New IPsec Remote Access …. 

        In this new policy you can define the networks (split or tunnel all), and the Remote Access users allowed to connect to this policy and the auth type. Based on the auth type you configure 

        the next step #3.

    3) On the Advanced tab, configure Local X509 Certificate or Preshared Key Settings (depending on your required configuration)

    4) Now Go to Remote Access->Advanced you configure DNS server, and Domain Name.

     

    After you configure the four steps above, login to the user portal as the user, download the configuration and import it Sophos Connect. Enable the connection and it works.

     

    Please let me know how it goes. Hope to hear back from you on how it went.

     

    Thank you,

    Ramesh

     

    PS: When connecting to UTM, there is ONLY function for which you will have to use Sophos Connect Admin and that is enable auto-connect. If you do not require auto-connect then you are good to go with the UTM policy configuration. Also note that on the UTM, you MUST configure IPsec Policy and NOT Cisco VPN Client.

  • We have a similar problem with some of our laptops. 

    Looking at the Connect Client status ( GUI) , this shows the correct IPV4 addresses for DNS

    Checking the details in a DOS / PS terminal shows 3 default IPV6 addresses for DNS.

    I have Sophserve ticket  9015034  open for this.

    "A number of our laptops (a mixture of new build and some that used to have SSL VPN) with the Sophos Connect Client V1.3  are not having the DNS settings for the TAP adapter set correctly.

    I have noticed that the DNS is being set to use 3 default IPV6 addresses and that the TAP adapter is being labelled as Sophos TAP adapter #2   
    I'll upload some screenshots which will assist
     
    comparing the connect client status (GUI)  , that shows the correct IPV4 address for DNS but those details aren't shown when displaying details of the network adaptor in a DOS or PS terminal.
    Have uploaded pics showing good & bad DNS. The good DNS was on one users WIn 7 laptop, the bad DNS was on her new WIn 10 laptop.  The other screenshots show TAP adapter #2  ( adapter #1 isn't present on the system - even showing hidden adapters)  and the IPV6 DNS"
     
  • Hello David,

     

    Please generate technical support report from the client after the connection is established on the problem laptop. Then PM me the report and I will take a look at this issue. Also are you terminating to XG firewall or the UTM? 

     

    The TAP adapter used by Sophos Connect is "Sophos TAP adapter" and that is correct. This is to differentiate it from the TAP adapter used by SSL VPN.

     

    Thank you,
    Ramesh

  • We've done some additional work on this.

    If TAP adapter IPV6 is switched off, the connect client doesn't connect  (failure to add route  ,(virtual IP range) prevented phase 2 completion

    switching TAP adapter IP V6 back on and manually entering IPv4 DNS entries, the connection establishes ok and we can browse internal resources.

     

    We have discovered that ONLY affected laptops are all running Windows 10 V1903.  

    We have just upgraded a laptop to V1903 and the connect client V1.3 ( which was working ok ) has just failed with exactly the same symptoms.

     

    Connecting to XG running V17.5 MR3  ( at the moment, due to u/g to MR7 shortly)

  • Hello David,

     

    We did the upgrade to v1809 to v1903 and did not encounter any problems. Can you please PM me the technical support report from the Client after the connection is enabled and connected. 

     

    Thank you,

    Ramesh

  • Hello David,

     

    Please send me a Technical support report from the Client that is not working. You can PM me the report. Also if you can provide some additional data on how many computers are having this problem. What were the steps they performed that resulted in this error condition. We have tried Win10 with this version and not having similar problem. It works for us on multiple machines we have upgraded so far.

     

    Thank you,

    Ramesh

  • Hello David,

     

    Not heard back from you on this. I need a Technical support report from the machine that has this problem. Create a technical support report after you establish the tunnel. You can PM the report to me. How many systems are having this problem?

     

    Thank you,

    Ramesh

  • Hello David,

     

    Not heard back from you on this. I need a Technical support report from the machine that has this problem. Create a technical support report after you establish the tunnel. You can PM the report to me. How many systems are having this problem?

     

    Thank you,

    Ramesh