I'm trying to set up a vpn connection between two xg. both firewalls have a fixed ip address and do not need nat.
both policies are 100% identical, however, i cannot establish a connection.
This thread was automatically locked due to age.
I'm trying to set up a vpn connection between two xg. both firewalls have a fixed ip address and do not need nat.
both policies are 100% identical, however, i cannot establish a connection.
afaik know, XG has issues on IPsec site2site when set to "initiate"
I got around it by setting XG to "respond only" and on the other end (Cisco ) an "ip sla " test ping to keep tunnel re-connecting.
But having 2 XGs, you can't set them both to initiate
also see
https://community.sophos.com/products/xg-firewall/f/vpn/84082/xg-sfos-16-01-2-ipsec-unable-to-initiate-connection-but-connects-if-set-to-respond-only
https://community.sophos.com/products/xg-firewall/f/vpn/78551/ipsec-vpn-site-to-site-cant-reconnect-automatically
s2s sslvpn might be workaround
afaik know, XG has issues on IPsec site2site when set to "initiate"
I got around it by setting XG to "respond only" and on the other end (Cisco ) an "ip sla " test ping to keep tunnel re-connecting.
But having 2 XGs, you can't set them both to initiate
also see
https://community.sophos.com/products/xg-firewall/f/vpn/84082/xg-sfos-16-01-2-ipsec-unable-to-initiate-connection-but-connects-if-set-to-respond-only
https://community.sophos.com/products/xg-firewall/f/vpn/78551/ipsec-vpn-site-to-site-cant-reconnect-automatically
s2s sslvpn might be workaround