Sophos XG Firewall

To configure the tunnel in the Sophos XG Management Portal:

  1. Log in to the Sophos XG Management Portal with the Administrator account.

  2. Add a local and remote LAN object:

    1. Go to Hosts and Services > IP Host, click Add and enter these:

      Field

      Enter

      Name Name for the object.
      IP Family IPv4
      Type Network
      IP Address Your local network and subnet.
    2. Repeat step a to add a remote LAN object:

      Field

      Enter

      Name Name for the object.
      IP Family IPv4
      Type Network
      IP Address Your remote network and subnet.
  3. Create an IPsec VPN connection:

    1. Go to VPN > IPsec Connections and select Wizard.

    2. In the Name field, enter a name for the connection, and click Start.

    3. For Select a connection type, select Site To Site and select Head Office.

    4. From the Authentication type list, select Preshared key.

    5. In the Local subnet field, enter the local LAN created earlier in the procedure.

    6. In the Remote subnet field, enter the remote LAN created earlier in the procedure.

    7. From the User Authentication list, select Disabled.

    8. Review the IPSec connection summary and click Finish.

  4. Set Status to Active.

  5. Add two firewall rules to allow the VPN traffic:

    1. Click Firewall and click Add Firewall Rule.

    2. In the Name field, enter a name for the rule.

    3. In the Description field, enter LAN-VPN.

    4. In the Source section:

      1. In the Source zones field, enter LAN.

      2. In the Source network and devices field, enter local subnet.

    5. In the Destination &services section:

      1. In the Destination zones field, enter VPN.

      2. In the Destination networks field, enter Harmony SASE_LAN.

    6. Click Save.

    7. Add the second firewall, click Firewall and click Add Firewall Rule.

    8. In the Name field, enter a name for the rule.

    9. In the Description field, enter VPN-LAN.

    10. In the Source section:

      1. In the Source zones field, enter VPN.

      2. In the Source network and devices field, enter Harmony SASE_LAN.

    11. In the Destination &services section:

      1. In the Destination zones field, enter LAN.

      2. In the Destination networks field, enter local subnet.

    12. Click Save.