This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall SSL VPN Site to Site to UTM 9

Figured I would try the new XG since I recently got a rental and thought I could try a VPN back to my UTM 9 device.

Well it's not going to well so far. I configured the VPN Server on the UTM 9 device. I added the Internal Network of the UTM 9 as the Local Network and the Remote Network is the WAN IP of my rental site. I set the protocol to UDP and the port to 4433. I also configured the virtual IP pool on a separate network than either of the two sites. I exported the .apc file.

On my XG I set the Portal HTTPS port to 4433 (I read in someone's guide that this is where the XG pulls the port for the site-to-site ssl from). I also set my SSL settings to UDP, gave a separate IPv4 Lease Range than the SSL pool on the UTM or either of the sites. Also the Cryptographic Settings on both the XG and UTM are the same. Compression is off on both devices. I created a new SSL site-to-site connection, gave it a name, upload the apc file and when I click the button it waits for a few seconds then says ssl client connection could not be updated. Nothing is dumped into the log, even with debug enabled (or at least I can't find it in the log, I may be looking in the wrong place.)

Any insight on what I can do to get this working, it seems straight forward.



Edited TAGs
[edited by: emmosophos at 6:01 PM (GMT -7) on 3 Jun 2021]
Parents
  • 1 thing I can see straight away is that your User Portal is already running on 4433 so may be having a port clash there. I'm trying to do a test myself between XG and UTM9 but I've been having weird errors so am pursuing.
  • I had read somewhere that there is no way to change the SSL VPN port by itself on the XG. I read that it uses the same port you supply for the SSL User Portal, that's why I set it to that, to match the setting for hte port on the UTM9.

    It isn't as simple as having to create a firewall rule to allow the traffic? I figured that would be doen automatically.
Reply
  • I had read somewhere that there is no way to change the SSL VPN port by itself on the XG. I read that it uses the same port you supply for the SSL User Portal, that's why I set it to that, to match the setting for hte port on the UTM9.

    It isn't as simple as having to create a firewall rule to allow the traffic? I figured that would be doen automatically.
Children
No Data