Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG VPN connection issue

Running XG 19.0.0 Build 317

I had the SSL VPN setup a year ago and did not use it much.

Had some changes to network over the last year. I have upgraded versions of XG and now have a new service provider.

I used the video to complete the setup. https://techvids.sophos.com/watch/6DSCq37grC8pbB6jt9QhH9 

I am unable to connect to the VPN using the Sophos Connect client.

I did notice that my XG has a WAN IP of 100.XXX.XXX.XXX and whatismyip shows 200.XXX.XXX.XXX.

I assume I am behind my local ISP firewall. Is this causing my issue?

I do have a DNS hostname and it resolves to the 200.XXX.XXX.XXX IP.



This thread was automatically locked due to age.
Parents Reply Children
  • HJason Etten

    If you have DDNS you can update under SSL VPN Global settings on the Override hostname field or you can enter your upstream router Public static IP (200.XXX.XXX.XXX.)and try .

    If user not getting connected share SSL VPN Logs from Sophos connect as per below snapshot : 

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • I tried the override hostname with the DDNS name I have and I also tried with the public IP of 200.XXX.XXX.XXX.

    This is the log from the connection with the override hostname using the IP address 200.XXX.XXX.XXX.

  • Port 8443 is blocked from your upstream ISP router as it is getting failed on logs

    Can you verify same ? you can checked port forwarding setting on your upstream router and make sure you allow TCP/UDP port 8443 for your Sophos XG WAN IP

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Sophos XG is my router. I don't have an upstream router.

    Do I need to create a firewall rule?

  • I have a fiber connection and an ONT box.

  • Please verify the port is closed or not open SSH go to option 4 and run tcpdump 

    console>tcpdump 'port 8443 

    share the output 

    Make sure Device access is enabled: 

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • I took a screen shot of one page. The screen refreshed multiple times so I took a snap of one.

  • If still not working we have to check with ISP for 8443 port is open from their end or not 

    Please take SSH access of Sophos XG Firewall as per the link : https://support.sophos.com/support/s/article/KB-000038697?language=en_US  and share tcpdump again share the logs.

    Please Go to System-->Admininstration --->Device Access and share a screenshot 

    To disable Login restriction, Go to Authentication > User Login restriction* and select Any node as highlighted below. 

    Have you filled out the default certificate on your XG firewall?

    Are you using the third-party signed certificate for SSL VPN? 

    Seems the issue is related to "server_certificate: certificate verify failed". Please check the default CA details are filled up or proper on XG to complete the cert verification.

    If possible you may try by regenerating default CA (by editing and saving it with details) but that will result in the regeneration of all your certificates and will restart the SSL VPN service and may require re-import of the configuration file of SSL VPN to the end-user machine to connect over SSL VPN. Please ensure you may do this activity in odd hours with proper downtime for the safer side, so anything may impact then you may restore the backup.

    Note: Before proceeding with default CA regeneration, you may take a backup of the current configuration for safety measures. 

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Can I use a different port if 8443 is blocked by ISP?