Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Will my VPN PSKs be overwritten?

Hi,

I've recently taken over administration of a Sophos XG Firewall appliance. The previous administrator has configured 3 VPNs with the remote gateway IP set to '*'. I can see that all 3 VPNs have established and are working. They are all using a PSK has an auth method.

I am now trying to create my own VPN connection. My configuration is specific with the remote gateway IP address so I use the single IP of the remote gateway I'm trying to build a VPN to from the same local interface the other 3 VPNs are building from.

When I try to save the new VPN configuration I get a warning that my PSK will also apply to all VPNs between the same remote and local gateway IPs. I'm worried as the local interface is the same and the existing 3 VPNs use a '*' as the remote gateway IP configuration. If I think like a programmer for a second, I can imagine that my specific IP address for my VPN might match as true against the '*' for whatever 'if' statements are running in the code in the background.

Can someone confirm whether this might be the case? If I look at the established VPN connections, their remote IP is different but the configuration still uses '*' which worries me. I do not have access to the other VPNs PSK.

Thanks

Szymon



This thread was automatically locked due to age.
  • Hi,  Thank you for reaching out to the Sophos community team. If the new 4th tunnel which you are creating has specific remote gateway IP in place of the wild card remote gateway "*" then it will not overwrite the PSK for those 3 tunnels. However, if you are updating PSK for any 1 tunnel where the remote gateway is * then the same PSK will be applied to the rest 2 tunnel as well where the remote gateway is *.




    Let us assume, If on the above remote gateway 1.2.3.4 if you have 2 existing tunnels ( on same listening Interface) then updating PSK to any 1 will apply the same PSK to both the tunnels.

  • Thanks for the swift response Vishal. I'll schedule an OOH maintenance just in case and create a backup. 

    Regards,

    Szymon