This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Support for IPv6 VPNs | DS-Lite | Unitymedia WAN Connection

Hey together, 

Simple Question: Does the XG supports VPN access with SSL or IPSec VPN and IPv6 ?

Background: We have several users which must use a WAN connection from Unitymedia or Vodafone (cable based) in their homeoffice.

The issue is, that these carriers are using DS-Lite, which is breaking the SSL VPN connection. No vpn connection is possible.

As a workaround we could use IPv6 VPN, if it possible with the XG. I didn't find any useful information regarding the documentation.

If there any other solutions, i'm happy for any ideas. 

Regards,

Jonny



This thread was automatically locked due to age.
Parents
  • Hello Jonnie,

    Thank you for contacting the Sophos Community!

    Yes SSL VPN and Sophos Connect using SSL VPN with IPv6 is supported.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hey 

    Thanks for your reply. Maybe IPv6 will help me out with this mess. Some questions about the use of IPv6 SSL VPN:

    • Do I need for testing purposes to override the Hostname at the XG SSL VPN Config with the public IPv6 Address or is sufficient to change the address at my .ovpn file?
    • Do I need some further changes at the .ovpn file? I already checked example configs for IPv6 from the OpenVPN Forum and there were some other parameters used?
    • If I use the Sophos Connect Client 2.0, which optain it's configuration from the user portal, how can I ensure that the Client is using IPv6 instead of IPv4? Using a Host AAA Entry? 
    • Is there a chance to get a failover function if a IPv4 connection fails to connect and use instead IPv6?  
    • Does the client lease mode correlate with the use of an public IPv6? In other words, can I use IPv4 for client ip but IPv6 for the connection through internet?  

    Thanks for your support!

Reply
  • Hey 

    Thanks for your reply. Maybe IPv6 will help me out with this mess. Some questions about the use of IPv6 SSL VPN:

    • Do I need for testing purposes to override the Hostname at the XG SSL VPN Config with the public IPv6 Address or is sufficient to change the address at my .ovpn file?
    • Do I need some further changes at the .ovpn file? I already checked example configs for IPv6 from the OpenVPN Forum and there were some other parameters used?
    • If I use the Sophos Connect Client 2.0, which optain it's configuration from the user portal, how can I ensure that the Client is using IPv6 instead of IPv4? Using a Host AAA Entry? 
    • Is there a chance to get a failover function if a IPv4 connection fails to connect and use instead IPv6?  
    • Does the client lease mode correlate with the use of an public IPv6? In other words, can I use IPv4 for client ip but IPv6 for the connection through internet?  

    Thanks for your support!

Children
No Data