This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

unable to connect with Cisco ASA 5585 site using site to site VPN connection to Sophos XG 230 firewall

Hi,

 

We are experiencing a challenge in trying to connect two sites by creating site to site VPN connection.

 

One site is using Cisco ASA 5585 while am using Sophos XG 230 firewall.

 

For the Cisco ASA they are getting the error that it cannot process the payload.

 

below are the screenshots for both the two devices logs and settings for my IPsec policies.

 

What could be the issue and how to go about resolving this.

 

     

3|Jul 30 2019|10:50:18|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:49:19|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:46:19|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:45:16|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:43:20|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:39:13|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:38:10|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:33:59|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:29:56|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:28:56|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:27:53|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:23:58|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:22:58|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:19:07|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:18:15|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:15:16|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:14:16|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:13:13|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:12:17|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:12:13|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:09:14|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:08:14|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:07:18|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|10:03:19|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:59:17|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:58:17|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:57:25|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:57:17|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:56:09|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:55:10|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:54:14|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:53:14|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:50:11|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:49:11|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:48:12|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:45:13|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:44:09|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:39:58|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1
3|Jul 30 2019|09:38:58|713048|||||IP = 41.72.216.190, Error processing payload: Payload ID: 1



This thread was automatically locked due to age.
  • Hi  

    Please make sure that IKE version should be the same at both the end.

    Please refer to the article - https://community.sophos.com/kb/en-us/127731

    On the Sophos XG Firewall, disable these options:

    1. Go to VPN > IPsec Connections and edit the configured IPsec profile.
    2. Under Gateway Settings, select Select Local ID for the Local ID Type field and select Select Remote ID for the Remote ID Type field. This will disable these options. It is disabled by default but if RSA or digital certificate is used, then it is required.
    3. Click Save.
    4. Go to VPN > IPsec Policies. Edit the IPSec policy used in the IPsec profile edited in the step above and disable Pass Data in Compression Format. (for setup with a third party vendor, it is recommended to disable it).
    5. Under Phase 2 section, select None for the PFS Group (DH Group). Only enable it if PFS is used.
    6. Click Save.

    On Cisco ASA, follow the steps below:

    1. Ensure that there isn't any PFS enabled. If PFS is used in XG, then it should be enabled in Cisco ASA also.
    2. Make sure IPSec policy transform set match with XG firewall's phase 2 parameters.
    3. If Cisco ASA is on a private network behind ISP modem or third party managed modem, then Disable NAT-T or NAT Traversal, otherwise keep it enabled.
    4. Test and update.