Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec site-to-site connection, two initiators

Hello Community,

the setup guides and the IPsec settings for our XGS3100 Firewall confuse me.

I want to setup a IPsec Site-to-Site tunnel to connect to our Site in another city. Both sites have new XGS3100 Firewalls running SFOS 19.5.1.

The configuration for IPsec Site-to-Site asks for a Gateway type, either Respond only or Initiate the Connection. Since we want both sites to be able to initiate the buildup if the p1 and p2 tunnels, as both sites host services that users of the other one occasionally need to access.

In what i have learned and experienced so far IPsec connections are initiated when packets on one side need it to be open, which can happen on either side, and have never before had to select an initiator and a responder. The resources i found so far haven't helped much either, stating that the central location should be the responder and that its not recommended to set both sites to intitiate the connection, but i can't figure out why, or what side effects that would have.

Does anyone have experience with setting up a site-to-site connection like this an ran into a similar issue, or have been taught wrong?

Cheers

Thorben



This thread was automatically locked due to age.
Parents
  • Essentially there is no problem in having both sites as initiators. 

    In bigger setups (like a star topology) you are likely want to configure the HQ as Respond only.
    The reason is: If you have Multiple firewalls connecting to your HQ, you do not want to have the HQ to reach out to one site, which could be offline for whatever reason. So the HQ is always reachable, but a BO could be offline for multiple times. So it will not "flood the logs with "unreachable". Sometimes the BO is not reachable anyway, due the NAT scenario. 

    __________________________________________________________________________________________________________________

Reply Children
No Data