Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.
Configuring at the Sophos XG Interface
-
Go to the Sophos XG interface and add a local and remote LAN
-
Go to Hosts and Services > IP Host and select Add to create the local LAN
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Go to Hosts and Services > IP Host and select Add to create the NordLayer LAN (10.6.0.0/20)
.webp?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
-
Create an IPsec VPN connection
-
Go to VPN > IPsec Connections and select Wizard.
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Give it a name and description
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Click Start to follow the wizard
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Select Site To Site as a connection type and select Head Office
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Set the Authentication Type to preshared key (generate this value as we will also need this value on our end)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Enter details for the local network, including the local WAN port, IP version, local subnet, and local ID
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Enter details for the remote network, including the remote VPN server, IP version, and remote subnet (10.6.0.0/20, or as displayed NordLayer_LAN)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
-
In the User Authentication Mode field, choose Disabled
-
Review the IPsec connection summary and click Finish
-
Click the Status (Active) to activate the connection
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
-
Add two firewall rules allowing VPN traffic
-
Go to Firewall and click +Add Firewall Rule
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
- Create two user/network rules as shown below
First Rule:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
Click Save.
Second Rule:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A20%3A01Z&se=2026-09-08T15%3A31%3A01Z&sr=c&sp=r&sig=DQlhhaQOPd7HhuxmVH3FiKeEmzFw%2FRGVzlFOchSBQUs%3D)
Click Save.
Ending note:
In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.
- Pre-shared key - you can generate it or we can provide it
- Encryption details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
- Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
- Remote subnet and mask (the subnet is used in your local network)
Note: In case you have any questions or issues, press 'Chat with support' at the bottom of the page.