Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XFRM Interface not editable

Hello,

I am creating a interface based IPSec Tunnel. 

When creating the connection

an xfrm interface is created.

This is the behaviour more or less described here: https://support.sophos.com/support/s/article/KB-000035839?language=en_US&c__displayLanguage=en_US

Unfortunately I am not able to configure the IP configuration. Really strange.



On the other side of the tunnel I was able to configure this.


I am even getting two green lights on both sides. However the remote node looks like a policy based connection (i):

Remote (Initiator):



Central (connected to):




Bug, feature or just a crappy firewall? Why is that not working as described? These things are really bothering me and getting on my nerves as I am pretty sure that I did this in that way one week ago with two other firewalls running on 18.5 MR-3 ...

The only difference might be that the working side is on 18.5 MR-3 and the other (remote) side is already updated to V19.

Regards,



This thread was automatically locked due to age.
Parents Reply
  • Yes. Essentially "Empty" in V18.5 means "Any". It is just another way to reflect it. Because if you look at V18.5 and the Tunnel, you see the tunnel is using ANY (0.0.0.0) for the Tunnel itself. So it means ANY. V19.0 simply reflect ANY. 

    So by using DUAL and not configuring anything, it stay "Empty" in V19.0 but it uses ANY. 

    {4118}: INSTALLED, TUNNEL, reqid 63, ESP in UDP SPIs: 
    {4118}: 0.0.0.0/0 === 0.0.0.0/0

    __________________________________________________________________________________________________________________

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?