Non Meraki VPN with Sophos XG310

TAxinte
Here to help

Non Meraki VPN with Sophos XG310

Hello everyone,

 

I've been trying to make a successfull connection between Meraki MX100 (15.44) and Sophos XG310 (18.5.2 MR-2 build380) for more than 1 week.

 

I tried to watch some videos, documentations from Cisco or Sophos but nothing works. The logs are pretty much useless and I'd like some professional advice from you guys.

 

I tried IKEv1 and 2, I tried all the IPsec policies combinations but nothing works.

I was able to see the green light as succesfull connection but I can't ping anything, plus the Sophos from the other side cannot make a connection to my meraki: "parsing IKE message from REMOTE_IP[500] failed"

 

I want to add that I actually have a meraki to meraki VPN active, does it have anything to do with a new non-vpn connection?

 

This is my last config that I left with the "green light" on.

 

TAxinte_1-1643384709050.png

 

TAxinte_2-1643384737969.png

 

 

2 Replies 2
Inderdeep
Kind of a big deal
Kind of a big deal

@TAxinte : I dont know the exact answer but check this thread if it helps

https://community.meraki.com/t5/Security-SD-WAN/Meraki-MX84-to-Sophos-XG-site-to-site-VPN/m-p/50779 

 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com

Thanks for the reply.  I finally solved the issue after weeks of trying.

 

Basically in the "Subnets" field I need to specify both local LAN and the remote LAN subnets. That is not documented on meraki. Sad but glad I managed to do it.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels