This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect: Received NO_PROPOSAL_CHOSEN notification from gateway

Hi Sophos Community,

I'm having trouble setting up Sophos Connect Client with an XG v18 firewall and am looking for your assistance.  This is the first client I'm setting up and did not have it working previously.

Client Sophos Connect Version: 1.4.45.1015

Client's scvpn.log:
2020-06-28 01:09:04AM [104308] dbg ConnectClient VPN state changed to connecting
2020-06-28 01:09:04AM [104308] dbg Starting tunnel (connecting)
2020-06-28 01:09:04AM [104308] dbg Connection to strongSwan has been established
2020-06-28 01:09:05AM [104308] dbg Initiating connection ConnectClient
2020-06-28 01:09:05AM [69352] dbg IKE being initiated to IP address XGPublicIP
2020-06-28 01:09:06AM [104308] err Tunnel initiate to XGPublicIP failed: 1009 - Received NO_PROPOSAL_CHOSEN notification from gateway: XGPublicIP
2020-06-28 01:09:06AM [104308] dbg Unloading configuration for connection ConnectClient
2020-06-28 01:09:07AM [104308] dbg Connection to strongSwan has been closed
2020-06-28 01:09:07AM [104308] dbg State is connecting, setting to disconnected
2020-06-28 01:09:07AM [104308] dbg ConnectClient VPN state changed to disconnected
2020-06-28 01:09:07AM [104308] dbg Sending notification: Received NO_PROPOSAL_CHOSEN notification from gateway: XGPublicIP

XG tcpdump port 500 or port 4500:
09:09:05.045178 PortB, IN: IP ClientIP.65426 > 10.1.1.4.500: isakmp: phase 1 I agg
09:09:05.045610 PortB, OUT: IP 10.1.1.4.500 > ClientIP.65426: isakmp: phase 2/others R inf
09:09:05.349830 PortB, IN: IP ClientIP.61760 > 10.1.1.4.500: isakmp: phase 1 I ident
09:09:05.350148 PortB, OUT: IP 10.1.1.4.500 > ClientIP.61760: isakmp: phase 2/others R inf



This thread was automatically locked due to age.
  • Update to this:
    My XG Firewall has a NAT'd WAN IP.  I was not supposed to create an interface alias with the public IP of the XG to use as the interface for Sophos Connect.  Instead I needed to use the WAN interface with its private IP.

    To get the client to connect to the XG I had to open the config file into Sophos Connect Admin and modify the Target Host to the public IP of the XG.