Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XFRM Interface not editable

Hello,

I am creating a interface based IPSec Tunnel. 

When creating the connection

an xfrm interface is created.

This is the behaviour more or less described here: https://support.sophos.com/support/s/article/KB-000035839?language=en_US&c__displayLanguage=en_US

Unfortunately I am not able to configure the IP configuration. Really strange.



On the other side of the tunnel I was able to configure this.


I am even getting two green lights on both sides. However the remote node looks like a policy based connection (i):

Remote (Initiator):



Central (connected to):




Bug, feature or just a crappy firewall? Why is that not working as described? These things are really bothering me and getting on my nerves as I am pretty sure that I did this in that way one week ago with two other firewalls running on 18.5 MR-3 ...

The only difference might be that the working side is on 18.5 MR-3 and the other (remote) side is already updated to V19.

Regards,



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    When you configured the Tunnel Interface IPsec, you chose IPv4 for the IP version and entered the SAs (Local Subnet) (Remote Subnet), which is why you can't configure the xfrm, since the tunnel already knows the SAs.

    "The XFRM interface is configured for specific local and remote subnets. You can't assign an IP address or routes to the interface."

    If you want to add an IP to the xfrm you would need to choose DUAL when configuring the IPsec Tunnel Interface.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hello EmmoSophos,

    DUAL - what does Dual mean? IPv4 and IPv6? 

    In 18.5 MR-3 it was possible to leave the network empty in case of a tunnel interface. In Version 19.0 this led to an error (with IPv4 selected). However it was possible to use "Any" for the networks. Is this working as well? At least it was possible to enter the IP Adress.

    Really strange. With each new version this behaves different. Let you development have a look on other vendors like fortigate where this behaves exactly like an interface.

    Regards,
    Bernd

  • Hello ,

    Yea that's right, either you can have restrict use IPv4 OR IPv6 or both depending upon your requirement. 
    And If you select specific subnets rather than "Any", you don't need to add routes or assign an IP address to the tunnel interface.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Thanks. Okay this is getting difficult.

    What happens if I want to use a group of networks there? Main purpose was to get this less static and operable without interruption of the policy based tunnels and to be able to use groups of network for configuration of the tunnels/SD-WAN routes and the firewall policies.

    What about the routing precedence then? Will I still be able to use SD-WAN on this interface when I configure Subnets on it? The current Routing precedence is Static route, SD-WAN route, VPN route on the remote firewall and Static route, VPN route, SD-WAN route on the central firewall. 

Reply
  • Thanks. Okay this is getting difficult.

    What happens if I want to use a group of networks there? Main purpose was to get this less static and operable without interruption of the policy based tunnels and to be able to use groups of network for configuration of the tunnels/SD-WAN routes and the firewall policies.

    What about the routing precedence then? Will I still be able to use SD-WAN on this interface when I configure Subnets on it? The current Routing precedence is Static route, SD-WAN route, VPN route on the remote firewall and Static route, VPN route, SD-WAN route on the central firewall. 

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?