Hello,
I got two questions that I could not resolve despite extensive reading the XG documentation.
On my XG, Sophos Client Connect is enabled, all connections are well established from windows remote hosts and Android mobile phones native vpn client using IPsec Xauth PSK.
1) To narrow down the attack surface, I would like to apply an additional geoip block filter to the VPN. I have different webservers behind the firewall where geoip blocking works great with XG. For VPN however, it seems that the rules are not handled by the firewall rules. How I can I configure this?
2) In addition to the PSK in IPsec, I would like to add an additional security layer by defining a Remote ID. As I've read in the documention, this could be DNS, IP or even an arbitrary string. So on the XG Client Connect configuration I choosed as Remote ID an email example (xyz@xyz.xyz) the same was used on the vpn client as IPsec ID. Unfortunately when adding these strings on both sides the connection can't be established. I am not sure how IP or DNS could work because the clients have dynamic IPs.
Thanks for shedding some light on these points.
Marc
This thread was automatically locked due to age.