--- title: "Setting up site-to-site on Sophos XG" slug: "site-to-site-sophos-xg" description: "Sophos XG interface adds a local and remote LAN.Add two firewall rules allowing VPN traffic.Set the Authentication Type to preshared key." status: "update" updated: 2026-09-08T13:08:42Z published: 2026-09-08T13:08:42Z canonical: "help.nordlayer.com/site-to-site-sophos-xg" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt > Use this file to discover all available pages before exploring further. # Setting up site-to-site on Sophos XG **Note**: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead. ## Configuring at the Sophos XG Interface 1. Go to the Sophos XG interface and add a local and remote LAN 2. Go to Hosts and Services > IP Host and select Add to create the local LAN ![Sophos XG firewall interface configuration form with LAN name, IPv4 network type, and subnet settings](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/01%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Go to Hosts and Services > IP Host and select Add to create the NordLayer LAN (10.6.0.0/20) ![Sophos XG IP host definition form with LAN name, IPv4 network type, and subnet configuration](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/03%20Setting%20up%20site%20to%20site%20on%20Sophos%20XG(1).webp) 1. Create an IPsec VPN connection 2. Go to VPN > IPsec Connections and select Wizard. ![Sophos XG VPN settings panel with IPsec policies tab and Wizard button highlighted](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/03%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Give it a name and description ![Sophos XG VPN connection wizard showing four-step setup with NordLayer name field highlighted](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/04%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Click Start to follow the wizard ![Sophos XG VPN wizard showing Remote Access connection type highlighted among connection options](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/05%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Select Site To Site as a connection type and select Head Office ![Sophos XG VPN wizard showing Site-to-Site connection type highlighted among three network topology options](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/06%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Set the Authentication Type to preshared key (generate this value as we will also need this value on our end) ![Sophos XG VPN authentication wizard with preshared key option selected and key input fields](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/07%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Enter details for the local network, including the local WAN port, IP version, local subnet, and local ID ![Sophos XG VPN wizard configuring local WAN port, IPv4 network, local subnet, and ID settings](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/08%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Enter details for the remote network, including the remote VPN server, IP version, and remote subnet (10.6.0.0/20, or as displayed NordLayer_LAN) ![Sophos XG VPN wizard configuring remote server IP, subnet, and Remote ID settings](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/09%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. In the User Authentication Mode field, choose Disabled 2. Review the IPsec connection summary and click Finish 3. Click the Status (Active) to activate the connection ![Sophos XG IPsec connections table showing active NordLayer site-to-site VPN with green status indicators](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/10%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Add two firewall rules allowing VPN traffic 2. Go to Firewall and click +Add Firewall Rule ![Sophos XG Firewall dashboard with IPv4 tab and Add firewall rule button highlighted](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/11%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) 1. Create two user/network rules as shown below ### First Rule: ![Sophos XG firewall rule form with NordLayer name, LAN VPN description, and Accept action configured](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/12%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) ![Sophos XG firewall source configuration with LAN zone and localsubnet network selected](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/13%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) ![Sophos XG firewall destination configuration with VPN zone, NordLayer LAN network, and Any services selected](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/14%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) Click Save. ### Second Rule: ![Sophos XG firewall rule form with NordLayer name, VPN-LAN description, and Accept action configured](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/15%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) ![Sophos XG firewall source configuration with VPN zone and NordLayer LAN network selected](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/16%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) ![Sophos XG firewall destination configuration with LAN zone, localsubnet network, and Any services selected](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/17%20Setting%20up%20site-to-site%20on%20Sophos%20XG(1).png) Click Save. ## Ending note: In order to finalize the site-to-site tunnel, please create a setup in [Sites tab of the NordLayer Control Panel](/v1/docs/site-to-site). - Pre-shared key - you can generate it or we can provide it - Encryption  details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2) - Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP) - Remote subnet and mask (the subnet is used in your local network) --- **Note**: In case you have any questions or issues, press '**Chat with support**' at the bottom of the page.