This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site VPN sophos XG to fortigate

Hi

i am trying to establish a site to site vpn between my main site running sophos xg and a remote site running a fortigate (behind a firewall)

obviously, the remote site needs to be the one that "calls" the main site.

both sides do not have static ip addresses and rely on dynamic dns hostnames.

whatever i do i cannot get the tunnel established although i repeatedly checked the settings are the same on each site.

same encryption, same DH, etc.

would love some help, if someone has screenshots to share - that would be awesome 



This thread was automatically locked due to age.
Parents Reply
  • Hi

     

    something doesnt make sense to me.

    here is a screenshot of a tracert from the server in the brach office to one of the devices on the main office side.

    (on of the vlans that has a red indicator in the above screenshot)

    it clearly shows that the fortigate is pushing the traffic out correctly. 

    seems like the traffic is lost on the sophos side

Children
  • But still not clear, how the SA are missing on XG? 

    I mean, you have to deploy a SA for each Network pinning. 

    See: https://en.wikipedia.org/wiki/Security_association

     

    If Fortinet uses other technologies to implement some kind of NAT, then you have to configure this properly. 

    But at the moment, only 1 of 4 SAs are correct published. Therefore XG will not push any traffic to those non existing Networks (because the SA and SPI is missing). 

    We are using the SAs to publish the routes. Therefore we need the correct SA.