<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.silbonetworks.com/index.php?action=history&amp;feed=atom&amp;title=IPSec_SOPHOS_and_SILBO</id>
	<title>IPSec SOPHOS and SILBO - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.silbonetworks.com/index.php?action=history&amp;feed=atom&amp;title=IPSec_SOPHOS_and_SILBO"/>
	<link rel="alternate" type="text/html" href="https://wiki.silbonetworks.com/index.php?title=IPSec_SOPHOS_and_SILBO&amp;action=history"/>
	<updated>2026-04-04T00:35:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.1</generator>
	<entry>
		<id>https://wiki.silbonetworks.com/index.php?title=IPSec_SOPHOS_and_SILBO&amp;diff=933&amp;oldid=prev</id>
		<title>Wikisysop at 08:28, 26 August 2024</title>
		<link rel="alternate" type="text/html" href="https://wiki.silbonetworks.com/index.php?title=IPSec_SOPHOS_and_SILBO&amp;diff=933&amp;oldid=prev"/>
		<updated>2024-08-26T08:28:10Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:28, 26 August 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l62&quot;&gt;Line 62:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 62:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Select connection type as “Ste-to-site”&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Select connection type as “Ste-to-site”&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Gateway type as “Respond only” as this firewall is going to respond to all the incoming VPN connections.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Gateway type as “Respond only” as this firewall is going to respond to all the incoming VPN connections.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Enable “Activate on Save” if you do not wish to enable this VPN on save. Also Create Firewall rule option can be enabled if you wish SOPHOS to create an Auto VPN firewall rule. [[File:IPsec General Settings .png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Enable “Activate on Save” if you do not wish to enable this VPN on save. Also Create Firewall rule option can be enabled if you wish SOPHOS to create an Auto VPN firewall rule. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/ins&gt;[[File:IPsec General Settings .png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Encryption:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Encryption:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l75&quot;&gt;Line 75:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 75:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Gateway address can be marked as “*” when IPSec destination IP address (Public IP) is unknown.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Gateway address can be marked as “*” when IPSec destination IP address (Public IP) is unknown.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Local and Remote ID type can be anything among available options, but we are using “DNS” which is a domain name so that we can use a name containing Alphanumeric character string in Local and Remote ID options. [[File:SOPHOS Gateway Settings.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Local and Remote ID type can be anything among available options, but we are using “DNS” which is a domain name so that we can use a name containing Alphanumeric character string in Local and Remote ID options. [[File:SOPHOS Gateway Settings.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Local and Remote Subnet should be selected if already created in System&amp;gt;Host and services&amp;gt;&amp;gt; IP Host option or can be created directly by clicking on “Add new item” [[File:SOPHOS Gateway Settings Step 2.png|frameless|620x620px]] Here we gave a name as Local_LAN and given a standard SOPHOS LAN subnet as shown in below image. [[File:Same way a remote Subnet can be configured.png|frameless|620x620px]] Same way a remote Subnet can be configured. In Local Subnet /24 network was configured for remote side /32 subnet can be selected in case of IPSec is created with a loopback interface on SILBO side, in case Local LAN is must then changes can be made accordingly. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/del&gt;[[File:Local Subnet Configuration.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Local and Remote Subnet should be selected if already created in System&amp;gt;Host and services&amp;gt;&amp;gt; IP Host option or can be created directly by clicking on “Add new item” &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/ins&gt;[[File:SOPHOS Gateway Settings Step 2.png|frameless|620x620px]] &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/ins&gt;Here we gave a name as Local_LAN and given a standard SOPHOS LAN subnet as shown in below image. [[File:Same way a remote Subnet can be configured.png|frameless|620x620px]] &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; &lt;/ins&gt;Same way a remote Subnet can be configured. In Local Subnet /24 network was configured for remote side /32 subnet can be selected in case of IPSec is created with a loopback interface on SILBO side, in case Local LAN is must then changes can be made accordingly. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;  &lt;/ins&gt;[[File:Local Subnet Configuration.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* NAT should be kept disabled.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* NAT should be kept disabled.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l146&quot;&gt;Line 146:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 146:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:Firewall from SILBO.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:Firewall from SILBO.png|frameless|620x620px]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:Traffic Rules.png|frameless|620x620px]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;How to create IPsec VPN in SOPHOS similar to exsisting VPN?&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Ans: Step 1 choose which VPN tunnel is correct and you want to create identical but a different tunnel&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:How to create IPsec VPN in SOPHOS similar to existing VPN Step 1.png|frameless|620x620px]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Step2: Make changes into these sections into a new duplicate tunnel.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:Make changes into these sections into a new duplicate tunnel..png|frameless|610x610px]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;Note:&#039;&#039;&#039; Use different loopback IP for each router in router/gateway in case of more routers are planned to communicate with same SOPHOS. Also make these changes “Name” it should be unique , “Local subnet”, “Local and remote Identifier” as per SOHOS configuration.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Wikisysop</name></author>
	</entry>
	<entry>
		<id>https://wiki.silbonetworks.com/index.php?title=IPSec_SOPHOS_and_SILBO&amp;diff=928&amp;oldid=prev</id>
		<title>Wikisysop: Created page with &quot;&#039;&#039;&#039;Prerequisite:&#039;&#039;&#039;  * SOPHOS firewall * SILBO Router or gateway * Static Public IP on wired internet connection * SIM card with active internet  Note: This document is prepared using XGS3100 (SFOS 20.0.1 MR-1-Build342) X31020MJG8C2MEF &amp;  SILBO 1.16_1.13 FW version.  == SOPHOS VPN setup == 1. Creating IPSec Policy/Profile.  Create a new IPSec tunnel by navigating to Configure&gt;&gt; Site-to-Site VPN &amp; click on IPsec profiles.  620x620px...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.silbonetworks.com/index.php?title=IPSec_SOPHOS_and_SILBO&amp;diff=928&amp;oldid=prev"/>
		<updated>2024-08-26T07:31:04Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Prerequisite:&amp;#039;&amp;#039;&amp;#039;  * SOPHOS firewall * SILBO Router or gateway * Static Public IP on wired internet connection * SIM card with active internet  Note: This document is prepared using XGS3100 (SFOS 20.0.1 MR-1-Build342) X31020MJG8C2MEF &amp;amp;  SILBO 1.16_1.13 FW version.  == SOPHOS VPN setup == 1. Creating IPSec Policy/Profile.  Create a new IPSec tunnel by navigating to Configure&amp;gt;&amp;gt; Site-to-Site VPN &amp;amp; click on IPsec profiles.  &lt;a href=&quot;/index.php/File:SOPHOS_VPN_setup.png&quot; title=&quot;File:SOPHOS VPN setup.png&quot;&gt;frameless|620x620px&lt;/a&gt;...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Prerequisite:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
* SOPHOS firewall&lt;br /&gt;
* SILBO Router or gateway&lt;br /&gt;
* Static Public IP on wired internet connection&lt;br /&gt;
* SIM card with active internet&lt;br /&gt;
&lt;br /&gt;
Note: This document is prepared using XGS3100 (SFOS 20.0.1 MR-1-Build342) X31020MJG8C2MEF &amp;amp;&lt;br /&gt;
&lt;br /&gt;
SILBO 1.16_1.13 FW version.&lt;br /&gt;
&lt;br /&gt;
== SOPHOS VPN setup ==&lt;br /&gt;
1. Creating IPSec Policy/Profile.&lt;br /&gt;
&lt;br /&gt;
Create a new IPSec tunnel by navigating to Configure&amp;gt;&amp;gt; Site-to-Site VPN &amp;amp; click on IPsec profiles.&lt;br /&gt;
&lt;br /&gt;
[[File:SOPHOS VPN setup.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
In the SOPHOS Firewall first we should create a Policy suitable for the need of architecture. Click on Add button once IPsec Profiles option window is available to configure.&lt;br /&gt;
&lt;br /&gt;
[[File:SOPHOS VPN setup 2.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Give a Name to the profile.&lt;br /&gt;
&lt;br /&gt;
Select “Key Exchange” &amp;amp; “Authentication mode” as per need.&lt;br /&gt;
&lt;br /&gt;
For unlimited key negotiation use “0” in “Key negotiation tries” option. Keep “Re-key connection” option enabled.&lt;br /&gt;
&lt;br /&gt;
[[File:SOPHOS General Settings.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Key Exchange and Mode configured as IKEv1 &amp;amp; Main Mode.&lt;br /&gt;
&lt;br /&gt;
Let us configure Phase 1 and then 2 configurations in the policy.&lt;br /&gt;
&lt;br /&gt;
The Phase 1 configuration and Phase 2 configuration can be same or different.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Phase 1 configuration:&lt;br /&gt;
&lt;br /&gt;
[[File:SOPhos Phase 1 Configuration.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Phase 2 configuration:&lt;br /&gt;
&lt;br /&gt;
[[File:SOPhos Phase 2 Configuration.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The DPD (Dead Peer Detection) Should be disabled when SOPHO Firewall is configured as VPN server and in case it is used as client then it can be enabled.&lt;br /&gt;
&lt;br /&gt;
Note: High encryption and authentication algorithm meaning less IPsec throughput and based on Internet speed on the Local and remote side the option should be selected.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Save the configuration so that this Policy can be used in IPsec VPN.&lt;br /&gt;
&lt;br /&gt;
Navigate to Configure&amp;gt;&amp;gt;Site-to-Site for IPsec VPN.&lt;br /&gt;
&lt;br /&gt;
* Click on Add or use Wizard to create IPSec VPN. [[File:Create IPSec VPN.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
General Settings:&lt;br /&gt;
&lt;br /&gt;
* Give a name to the VPN in this example we are giving “Test3” name.&lt;br /&gt;
* Configure it as IPv4 as this document is for IPv4 only.&lt;br /&gt;
* Select connection type as “Ste-to-site”&lt;br /&gt;
* Gateway type as “Respond only” as this firewall is going to respond to all the incoming VPN connections.&lt;br /&gt;
* Enable “Activate on Save” if you do not wish to enable this VPN on save. Also Create Firewall rule option can be enabled if you wish SOPHOS to create an Auto VPN firewall rule. [[File:IPsec General Settings .png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Encryption:&lt;br /&gt;
&lt;br /&gt;
* The profile should be correctly selected.&lt;br /&gt;
* The same IPsec Profile / policy “SILBOIPSEC” is selected for this IPsec VPN.&lt;br /&gt;
* Select the Authentication type as PSK (Preshared Key). [[File:SOPHOS Encryption.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Gateway Settings:&lt;br /&gt;
&lt;br /&gt;
* The Listening IP is the Public IP or the WAN IP on which IPSec ports are forwarded from Public IP. i.e. UDP 4500 and UDP 500.&lt;br /&gt;
* Gateway address can be marked as “*” when IPSec destination IP address (Public IP) is unknown.&lt;br /&gt;
* Local and Remote ID type can be anything among available options, but we are using “DNS” which is a domain name so that we can use a name containing Alphanumeric character string in Local and Remote ID options. [[File:SOPHOS Gateway Settings.png|frameless|620x620px]]&lt;br /&gt;
* Local and Remote Subnet should be selected if already created in System&amp;gt;Host and services&amp;gt;&amp;gt; IP Host option or can be created directly by clicking on “Add new item” [[File:SOPHOS Gateway Settings Step 2.png|frameless|620x620px]] Here we gave a name as Local_LAN and given a standard SOPHOS LAN subnet as shown in below image. [[File:Same way a remote Subnet can be configured.png|frameless|620x620px]] Same way a remote Subnet can be configured. In Local Subnet /24 network was configured for remote side /32 subnet can be selected in case of IPSec is created with a loopback interface on SILBO side, in case Local LAN is must then changes can be made accordingly.  [[File:Local Subnet Configuration.png|frameless|620x620px]]&lt;br /&gt;
* NAT should be kept disabled.&lt;br /&gt;
&lt;br /&gt;
== Configuring SILBO Router/gateway: ==&lt;br /&gt;
Login to router using default IP 192.168.10.1 for gateways Default IP address is 192.168.9.1 and default credentials are admin/admin.&lt;br /&gt;
&lt;br /&gt;
[[File:Log In.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Once login we can see the FW version.&lt;br /&gt;
&lt;br /&gt;
[[File:IA44B System.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Change the IP address to required IP, in this testing we are using 192.168.11.1 IP address.&lt;br /&gt;
&lt;br /&gt;
To do that Navigate to Settings&amp;gt;&amp;gt;Network from 192.168.10.1 to 192.168.11.1 and save / update.&lt;br /&gt;
&lt;br /&gt;
For loopback configuration Navigate to Settings&amp;gt;&amp;gt;Network&amp;gt;&amp;gt;Loopback IP Settings and configured IP address and NetMask as shown.&lt;br /&gt;
&lt;br /&gt;
Save and then Update which is must for Network section.&lt;br /&gt;
&lt;br /&gt;
[[File:Loopback IP Settings.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Upon IP changed configure VPN.&lt;br /&gt;
&lt;br /&gt;
Navigate to &amp;gt;&amp;gt; Settings&amp;gt;&amp;gt;VPN&amp;gt;&amp;gt; IPsec&amp;gt;&amp;gt; and do as per below images&lt;br /&gt;
&lt;br /&gt;
[[File:Fortigate firewall VPN config.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
And configure IPSec as per SOPHOS configuration.&lt;br /&gt;
&lt;br /&gt;
[[File:IPSec as per SOPHOS .png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Once all the configuration is correctly configured and clicked on save button device will show VPN configuration &amp;gt;&amp;gt; General settings.&lt;br /&gt;
&lt;br /&gt;
Save and then navigate to VPN&amp;gt;&amp;gt;Ipsec setting page and click on update.&lt;br /&gt;
&lt;br /&gt;
IPsec will come up after some time and it can be seen as established as shown below.&lt;br /&gt;
&lt;br /&gt;
[[File:Ipsec in SILBO Router.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Also, in SOPHOS it can be seen as below.&lt;br /&gt;
&lt;br /&gt;
[[File:Sophos VPN Dashboard.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
To Ping server LAN, navigate to features&amp;gt;&amp;gt;Others and give LAN IP and ping.&lt;br /&gt;
&lt;br /&gt;
If the ping is not working then check the firewall side settings whether the ping is allowed or not.&lt;br /&gt;
&lt;br /&gt;
[[File:Others .png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; In SOHOS The below Firewall Rules should be present if not then should be created. &lt;br /&gt;
&lt;br /&gt;
Navigate to Protect&amp;gt;&amp;gt;Rules and Policies&amp;gt;&amp;gt;Firewall Rules in SOPHOS.&lt;br /&gt;
&lt;br /&gt;
[[File:Firewall Rules in SOPHOS.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
To create a new firewall rule click on “Add firewall rule ”. &lt;br /&gt;
&lt;br /&gt;
LAN to VPN Overview.&lt;br /&gt;
&lt;br /&gt;
[[File:LAN to VPN Overview.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
Basically the below configuration should be added without touching other configuration options in the firewall rule.&lt;br /&gt;
&lt;br /&gt;
for Both LAN to VPN and VPN to LAN.&lt;br /&gt;
&lt;br /&gt;
[[File:LANtoVPN and VPNtoLAN.png|frameless|620x620px]]&lt;br /&gt;
&lt;br /&gt;
The Firewall from SILBO should also should be as below.&lt;br /&gt;
&lt;br /&gt;
[[File:Firewall from SILBO.png|frameless|620x620px]]&lt;/div&gt;</summary>
		<author><name>Wikisysop</name></author>
	</entry>
</feed>