Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ipsec vpn for intranet

Hello, all i just wanted to ask if we need to configure ipsec VPN when we have intranet connection to that site since the data is very important so will the transaction between the two be insecure.



This thread was automatically locked due to age.
Parents Reply
  • Hi Kaeyana,

    Kindly specify the Public IP of  the Remote Gateway and not as a wildcard 

    For reference:

    Sophos XG IPsec Configuration (Responder Only)

    Local Gateway - WAN Interface

    Remote Gateway - Remote End device Public IP address

    Remote End device IPsec Configuration  (Initiate the tunnel)

    Local Gateway - WAN Interface

    Remote Gateway -  Remote End device Public IP address

     

    For more reference kindly check the following

    KB: https://soph.so/Tjc9qA

    Techvids: https://soph.so/moKL3t

Children
  • The end device has the dynamic ip so can't specify one so can i just use the intranet static ip since the intranet is connected anyway to the router from sophos

  • Hi Kaeyana,

    I see. Thank you for the information. 

    • Kindly make sure that configuration settings and IPSEC policy configured is proper and no mismatch in authentication and encryption parameters at both ends.

    • Check logs for both site
    • If possible can you share the log details in /log/strongswan.log.
    • Check DNAT rule that includes services (udp 500/4500 Proto 50)