Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site VPN

I am able to establish a site to site connection from my Sophos XG v16 to a Barracuda Firewall however it won't pass any traffic.  I have verified the rules and networks are setup on both devices.  The barracuda worked with my previous Sophos UTM and it works currently with a Mikrotik.



This thread was automatically locked due to age.
Parents Reply Children
  • Ok so I have made some advancements.  I can see that I am in fact sending traffic to the Barracuda firewall.  However it is not sending any traffic back to me.  So it looks like this is a Barracuda issue.  I will be opening a ticket with them tomorrow to look into the issue.  Hopefully once i have this working I will post what if any additional changes were needed as well as my final configuration settings.

  • Ok so after dealing with Barracuda support for over an hour we had a successful VPN connection that was passing traffic and then two hours later the Sophos lost the VPN connection and it is back to not working. Traffic is being sent from the XG to the Barracuda and the Barracuda is sending traffic back however the XG doesn't see the traffic coming back yet it has no issues with getting the VPN up and running.

    So I am not back to square one but I still don't have a working VPN on the XG that did work on the UTM without any issues.

  • HI Michael, 

    If the tunnel is established and the Barracuda is sending the traffic to the XG appliance , you may need to run the packet capture on the console or on  UI for the same command . 

    Console > tcpdump 'host <Remote network> or port 4500 or port 500

  • I have done that i see the following when looking at port 500:

     

    20:53:46.962626 Port2, IN: IP "REMOTE IP".500 > "LOCAL IP".500: isakmp: phase 2/others ? inf[E]
    20:53:46.962987 Port2, OUT: IP "LOCAL IP".500 > "REMOTE IP".500: isakmp: phase 2/others ? inf[E]

     

    There is nothing for port 4500.

  • HI Michael, 

    Could you check if you are receiving the ESP packets from the remote location , command is 

    console> tcpdump 'host <Remote Public address> 

  • Same exact results just port 500, and yes I ran the command without defining the port option.

     

    Also both sides are reporting the tunnel as being up.