Documentation Index

Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt

Use this file to discover all available pages before exploring further.

Setting up site-to-site on Sophos XG

Prev Next

Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.

Configuring at the Sophos XG Interface

  1. Go to the Sophos XG interface and add a local and remote LAN

  2. Go to Hosts and Services > IP Host and select Add to create the local LAN

Sophos XG firewall interface configuration form with LAN name, IPv4 network type, and subnet settings

  1. Go to Hosts and Services > IP Host and select Add to create the NordLayer LAN (10.6.0.0/20)

Sophos XG IP host definition form with LAN name, IPv4 network type, and subnet configuration

  1. Create an IPsec VPN connection

  2. Go to VPN > IPsec Connections and select Wizard.

Sophos XG VPN settings panel with IPsec policies tab and Wizard button highlighted

  1. Give it a name and description

Sophos XG VPN connection wizard showing four-step setup with NordLayer name field highlighted

  1. Click Start to follow the wizard

Sophos XG VPN wizard showing Remote Access connection type highlighted among connection options

  1. Select Site To Site as a connection type and select Head Office

Sophos XG VPN wizard showing Site-to-Site connection type highlighted among three network topology options

  1. Set the Authentication Type to preshared key (generate this value as we will also need this value on our end)

Sophos XG VPN authentication wizard with preshared key option selected and key input fields

  1. Enter details for the local network, including the local WAN port, IP version, local subnet, and local ID

Sophos XG VPN wizard configuring local WAN port, IPv4 network, local subnet, and ID settings

  1. Enter details for the remote network, including the remote VPN server, IP version, and remote subnet (10.6.0.0/20, or as displayed NordLayer_LAN)

Sophos XG VPN wizard configuring remote server IP, subnet, and Remote ID settings

  1. In the User Authentication Mode field, choose Disabled

  2. Review the IPsec connection summary and click Finish

  3. Click the Status (Active) to activate the connection

Sophos XG IPsec connections table showing active NordLayer site-to-site VPN with green status indicators

  1. Add two firewall rules allowing VPN traffic

  2. Go to Firewall and click +Add Firewall Rule

Sophos XG Firewall dashboard with IPv4 tab and Add firewall rule button highlighted

  1. Create two user/network rules as shown below

First Rule:

Sophos XG firewall rule form with NordLayer name, LAN VPN description, and Accept action configured

Sophos XG firewall source configuration with LAN zone and localsubnet network selected

Sophos XG firewall destination configuration with VPN zone, NordLayer LAN network, and Any services selected

Click Save.

Second Rule:

Sophos XG firewall rule form with NordLayer name, VPN-LAN description, and Accept action configured

Sophos XG firewall source configuration with VPN zone and NordLayer LAN network selected

Sophos XG firewall destination configuration with LAN zone, localsubnet network, and Any services selected

Click Save.

Ending note:

In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.

  • Pre-shared key - you can generate it or we can provide it
  • Encryption  details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
  • Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
  • Remote subnet and mask (the subnet is used in your local network)

Note: In case you are experiencing different results, make sure that you have you carefully gone through all the steps. Having said that, in case the issue persists please feel free to contact our 24/7 customer support team.

Can't find what you need?

Live chat

Contact our support to solve an issue live.

Chat functionality relies on cookies. By starting the chat, you agree to their use. Learn more in our Cookie Policy.