Hi, I currently have a deployment with about 40 sites connecting to a data center via internet and MPLS. Our data center MX is behind a Sophos UTM in one armed concentrator mode. On the Sophos UTM i created all the firewall rules for the ports, which the MX in dashboard under help -> firewall info is suggesting, but it seems that auto-vpn in automatic mode is not working properly. I can also see in the logs of the UTM that the MX is trying to communicate over a lot of UDP highports - i guess this is related to the "automatic mode". However, I'm not a big fan of those "any-any" firewall rules, so i am wondering if there is a recommendation for what ports are needed to be open from the MX to the internet and what ports may be needed to be forwarded from the internet to the MX appliance. i couldn't find any clear statement in the documentation on that. Thank you. Best regards Tobi
... View more