Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec head scratcher

Got a question for the wizards here:

I have an XG210 at my office, and an XG home on a computer at my house, and I am trying to create a site-to-site IPsec tunnel.  I configure the tunnel on both ends, activate the connection, connection comes up, Phase 2 is good and I am sharing local and remote subnets between the two.  I create a static route on both sides, create firewall rules to allow VPN to LAN and LAN to VPN.  I can ping each firewall from the other firewall using the Diagnostics page.  So far so good.  However, now things fall apart.  I can ping network hosts across the VPN from the XG home firewall diagnostics.  I cannot ping network objects across the VPN from the XG210.  I cannot ping anything from clients on either side of the network. 

This seems like a firewall rule issue but I have used these exact same rules when I had a pfSense box on the other side and it worked fine.  Anybody have any ideas on how I can further debug?



This thread was automatically locked due to age.
Parents
  • What about other protocols beside ICMP pings. I guess your guess may be right and its a firewall problem. Can you please check how 'Ping/Ping6' has been configured on the page:

    Administration => Device Access

Reply
  • What about other protocols beside ICMP pings. I guess your guess may be right and its a firewall problem. Can you please check how 'Ping/Ping6' has been configured on the page:

    Administration => Device Access

Children