– Today’s article will guide you on how to configure and create an SSL VPN connection between two Sophos XG Firewall devices. Configuration components: SSL VPN Server, install and connect to SSL VPN Client.
I/ Network diagram for the article:
– In the model above we have 2 Sophos Firewall devices (FW 1 and FW 2), we will configure Firewall 1 as SSL VPN Server and Firewall 2 is SSL VPN Client.
II/ Configure SSL VPN Server on Sophos Firewall 1:
– Add network layer Local and Remote LAN. Go to the page Web GUI > Hosts and Services > IP Host > click Add to add a new Local LAN network layer.
– Create additional network layers remote LAN, enter Hosts and Services > IP Hosts > click Add.
III/ Create Site-to-Site SSL VPN connection:
– Go to page VPN > SSL VPN(Site-to-Site) > click Add.
- Connection Name: name of this tunnel.
- Use static virtual IP address: tick if using dynamic IP address. This IP configuration cannot overlap with any host on the LAN (eg: 192.168.254.254).
- Local Networks: select network layer Local LAN/ hosts so they can go through the tunnel.
- Remote Networks: select network layer Remote LAN/hosts to connect to Site 2 using tunnel.
– Click Save Now that the connection tunnel has been created, click on the download icon to the right of the newly created VPN.
– A pop-up window will appear, click Download to download a file used to configure clients. This file will be given the format *.apc. You can also encrypt files with a password, if ticked Encrypt configuration file.
– Add rule to allow traffic inbound & outbound of SSL VPN passes through. Enter the path Firewall > +Add Firewal Rule > select User/Network rule.
III/ Configure SSL VPN Client on Sophos Firewall 2:
– Create a new SSL VPN Client connection. Go to the page Web GUI > VPN > SSL VPN(Site-to-Site) > click Add.
- Connection Name: name of this tunnel.
- Configuration File:Click Choose File to load files *.apc downloaded on SSL VPN Server.
- Password: if you set a password in the download step, enter the password.
- Use HTTP proxy server: Use option if the system goes through a web proxy.
- Override peer hostname: tick if the server’s hostname is not publicly routed by DNS or public IP.
– Add rule to allow traffic inbound & outbound of SSL VPN passes through. Enter the path Firewall > +Add Firewal Rule > select User/Network rule.
IV/ Results:
– Tunnel SSL VPN will display a green status if it is active. If the status is red, you should check the settings again.
– When active, you can also see traffic connecting through the SSL VPN tunnel.
—Thank you for following this article—
Xem tiếp...