Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec Site-to-Site on XG18 not working

Hi,

I installed Sophos SFOS with XG18 on my 2 SG210 Appliances, becuase we need to have more then 1 DHCP-Relay.

But even with Firewall XG the IPsec Site-to-Site won´t work.

I configured it for 3 VLANs like mentioned here:
https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/VPN/SiteToSiteVPN/VPNConfigureSiteToSiteIPsecNAT/index.html

IPsec is probably connected, but doesn´t transfer data.
Not even a Ping from one site to another is possible.
Inbound and outbound rules in firewall and also report-section don´t show transmitted data.

Do I have to do some additional NATing?

I need it to run because our backoffice is offline actually without connection to HQ.

Also there have to be in every Vlan a DHCP-Relay to the same Network at HQ

Thanks for help



This thread was automatically locked due to age.
Parents Reply
  • Hi superfun2k22

    As per the snapshot you have private IP on Port 2 on each side of Sophos XG

    I'm suspecting your ISP router is blocking ports for IPSec to work

    Have you forwarded ports 500 and 4500 on your upstream router connected on Port 2?

    Please check the logs on both  firewall CLI to verify the same : 

    console> tcpdump 'port 500 or 4500 

    console>show vpn IPSec-logs and share the logs with us 

    Tip: make sure you have static Public IP on Sophos XG or DDNS to make IPSec VPN Tunnel up

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?