I've setup is as follows:
2x vNics in VM "Briged" and "Host.. on Sophos. "Briged" is only for WAN access eventually, (if i can get it to work)
1x vNic on same VM host subnet for map sharing tog VPN.
Installed Sophos ISO, and changed 172.16.16.16 IP to that from VMWare (host only (172.16.253.x).. It took me ages to relieaze first of no matter what, i couldn't change VPN range o sophos from 10.0.x to 172.x (aka bring it into the same range. and then i release later i guess that could be for security reasons, so i just left it "as is"), you know just to make network more simpler instead of doing over multiple ranges..
Configured CA, VPN/user and firewall rules, and downloadedsophos client.
Testing from within LAN on this 2nd VM, i connect via client okayed it shows up under "Current ACtivuties" on Sophos..
However, because 'm physicaly on the Lan, i don't think i could use the same "trick" to to go over WAN..,. (eg.... browse to external IP on purpose/user portal, and try downloading and connect that way (unsure it routing will loopback, ir it would just "assume"
In any case i got LAN to work... Now comes the hard part... Realising and testing OpenVPN on iPhone was a total waste, *for now* i wanna try and connect WAN side... What ports do you need to forward ? Are they the same ones regardless of connection method ? weather you use SSL Remote or ovn config ?
I actually logged into my friend Sophos and download HIS .ovpn. Comparing his and mine in text edit may of pinpointed the issue..
At the bottom of his, he has "remote = <pubic IP address>" added in addition to the usual LAN address which i have... But i'm missing WAN IP from config.
I this this could be the problem,, and if i just add it to mine, and save, Sophos won't connect.... (again,, presumably i need sort out WAN thing first...)
I can access portal using WAN IP no problem, but still uncertain because i am physically on LAN if you know what i mean,.
I'm close... but i could use some suggestions.
I've looked in Log Viewer but its either useless, or everything must appear fine, because there is no entries at all.... which probably assumes its not even making it.
This thread was automatically locked due to age.