Monday, October 29, 2018

Stuck on Setting up SSL VPN on Sophos XGS [Advice]

I haven't tried this in Sophos' CLI

I was tasked with setting up a VPN connection between our satellite office to our main office.

The goal is to create SSL VPN accounts for satellite office users on an as needed basis. Depending on who they are, they get access to different internal servers.

Easy, right? However, I seem to be butting heads against Sophos XGS' GUI.

I followed this video: https://www.youtube.com/watch?v=6qc272Pgulw

I've set up plenty of VPN connections before, but my prior experience with my previous employer is Cisco Meraki.

When I set the IPV4 lease range of (for example) 10.10.0.1 - 10.10.0.50, I get this error message:

Network with the same IP address as start lease IP already exists, choose a different IP address 

Here's the LAN DHCP server - https://i.imgur.com/jMKEwlF.png

Here's my current SSL VPN scope that I want to change to 10.50.0.1 - 10.50.0.50, but can't - https://i.imgur.com/p2uHovY.png

My gut tells me I need to change the end IP on the LAN DHCP server, and give the addresses outside of the DHCP scope to the SSL VPN range, but my boss says I shouldn't have to do that.

In Cisco Meraki you could do this, but here I can't. Please let me know if I'm on the right path, or If I'm completely wrong.

Tl;dr -- I'm an IT Junior that doesn't want to break his work's network.



No comments:

Post a Comment