I'm wondering if somebody could try a remote connection with a free ipsec client to check my sanity.
I have this open in another thread but I fear it would get lost. Sophos support is about as much use as a chocolate teapot. They've taken nearly 12 weeks to come back with an answer that I just can't agree with as it's wrong. To me they are in denial.
All I require from somebody is to create (or try to create) a remote connection using a shrewsoft ipsec vpn client. It can be downloaded from here and is free:
https://www.shrew.net/download
There is a guide on the internet to make a connection to the UTM as well which is here:
http://www.virtualizationhowto.com/2015/01/connect-shrew-soft-vpn-client-sophos-ipsec-vpn/
It is simple and should take no more than a few minutes to do.
My problem:
1. I can only connect up if I put "Internet" or "Any IPv4" in the UTM local networks. Now, I think this can be down to the Shrewsoft client as I'm not specifying any networks in its config tab. Problem is if I do specify the network in the shrewsoft client and match it with that of the local network under the UTM, it won't connect.
2. Because I have to put "Internet" or "Any IPv4" in the UTM for it to connect, it gets full access to my network
Now I don't want that as I want to restrict these users to specific hosts. Here's the strange bit:
1. If I authenticate with certificates, You get the option to use "Automatic firewall rules". If you just choose PSK, there is no option to use "Automatic firewall" rules. Very strange as you would think you would want to apply firewall rules regardless of authentication?? PSK with Xauth is the same!
2. Now the above issue (which is strange) would not be a problem if you had to apply manual rules to allow access. But this isn't the case. Without any rule in sight, the remote user has FULL access by default. Now that is a serious flaw in my eyes. Put a block rule in to block this network as the top rule? Doesn't make a difference!
Putting a rule in is about as much use as calling Sophos support...... Don't expect it to work.
I've been more than patient with Sophos support on this one and when they come back with it must be an issue with my configuration (which they browsed over and couldn't see the issue), it really starts to pee you off. We've spent £50k with them and were due to spend more as well as recommend them to our regional partners.
That is now on hold due to their extremely poor support alone (let alone this issue)
We will plod away with this one in the meantime but I'd really appreciate it if somebody could give this a shot just to confirm they are seeing what I am.
This thread was automatically locked due to age.