Hello,
We are in the process of investigating Sophos XG firewall to replace our pfSense firewalls. One of the critical things is that the remote Sophos XG appliances need to be able to connect to our virtual pfSense firewall in our datacenter (currently we have pfSense appliances onsite and main virtual pfSense in datacenter. All is connected with OpenVPN Site-2-Site).
I've managed to setup a virtual XG appliance and create the correct .apc file so that it can be imported into the Sophos XG firewall and it connects to the pfSense openVPN server. However, during the connection, more than 100 routes are pushed to the client. By default, openVPN only allows 100 routes for a VPN Connection, but we can manage that by adding the option max-routes 200 to override this. That's also what I see in the vpn log of XG firewall:
Tue Jan 15 15:08:17 2019 [16513] MANAGEMENT: Client disconnected
Tue Jan 15 15:08:17 2019 [16513] OpenVPN ROUTE: cannot add more than 100 routes -- please increase the max-routes option in the client configuration file
Tue Jan 15 15:08:17 2019 [16513] Exiting due to fatal error
Can someone tell me where I can add the option "max-routes 200" on the XG firewall? I can't find it in the UI but it will probably be possible somewhere in a config file, but I can't seem to find it.
P.S. I know it's best to keep the routes below 100, but for now that is not possible. Once all remote locations are converted from pfSense to Sophos, we can convert our datacenter and optimize the routing and vpn connections.
Thanks a lot.
Michiel.
This thread was automatically locked due to age.