Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP over IPSec / Windows 10 Mobile

Hello Community;

I am hoping that someone can help me get over a small hurdle I have with setting up a working L2TP over IPSec remote access connection.

Background:

1. I wish to connect to my home network securely from various mobile devices.
2. I have a functioning SSL VPN configuration for use with my Android Mobile Devices. There are numerous SSL VPN apps available on Android.
3. I also wish to be able to connect to my home network via Windows 10 Mobile devices. Windows 10 Mobile does not appear to have SSL VPN clients available as far as I could find, therefore I wish to configure Sophos XG to accomodate L2TP over IPSec in order to support available VPN connection methods on Windows 10 Mobile.

Current Situation/Problem:
1. Endpoint: Sophos XG (firmware 16.01)
2. I have configured L2TP (Remote Access) with Preshared Key in Sophos XG
3. I seem to be able to successfully establish a connection between remote client and XG (Green lights on Status/Active and Status/Connection) , but I don't think I am passing any data between client and internal network (LAN). Ping test from remote client to internal IP addresses fails.

I assume that I need to configure some Firewall rules to enable traffic to pass between LAN Zone and the L2TP VPN Zone, but I have not found any helpful documentation on how to do so, assuming it is required.
I am also assuming that SSL VPN and L2TP VPN services can run concurrently on XG and without interference?

Can someone please help fill in the missing pieces for this process?
If I can get this working, I will contribute a how to video on the subject for other community members.

Thank You

M. Somerville



This thread was automatically locked due to age.
Parents
  • Hi Michael,

    Welcome to the Sophos Community.

    Configure a FW-rule, VPN-ANY-LAN and apply MASQ in the rule. This will route the traffic through VPN towards the LAN zone. Remember not to select the match known user option in this rule. If that doesn't help, check #1 in my guide here and post the output of packet capture and drop-packet-capture.

    Thanks

Reply
  • Hi Michael,

    Welcome to the Sophos Community.

    Configure a FW-rule, VPN-ANY-LAN and apply MASQ in the rule. This will route the traffic through VPN towards the LAN zone. Remember not to select the match known user option in this rule. If that doesn't help, check #1 in my guide here and post the output of packet capture and drop-packet-capture.

    Thanks

Children