This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange behavior when using sophos connect vpn.

hi there,
of 80 users who use "Sophos connect", we see behavior in about 10 which we currently do not understand.

there are two locations, locations A and B, both locations are connected by an IPSec tunnel, V17.5 MR11.
Most users connect to location "B" with the "Sophos connect". The Exchange Server is located in location "A".

the following behavior can now be seen in the 10 affected users.
if they have connected to location "B", no TSL / SSL to Exchange is possible, neither Outlook nor OWA website works (ping works).
if these affected users use the SSL VPN client on the same FW (same fw rules), everything works again.
there is also no problem if the affected user connects to location "A" in which the Exchange Server is located.

The question is, why do these 10 users have problems with TLS / SSL when they use "Sophos connect" and are connected to location "B"?
A ticket has been open here for 4 weeks, but without a solution.

Does anyone know of such problems, thanks for any help.



This thread was automatically locked due to age.
Parents Reply
  • Hi  

    The reason why it works fine at Site A is because the resources needing access to are local to that XG where the Sophos Connect terminates.  The reason why it does NOT work at Site B is because the resource needing access is at Site A behind an IPsec tunnel.  IPsec tunnels that are in pre-v18 are policy based IPsec tunnels.  The XG binds to the ipsec0 interface which has an IP address in the 169.254.x.x range....which is non-routable.  This is the reason why you need a NAT for the system routed/generated traffic.

    Thanks!

    KingChris
    Community Support | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

Children