Non Meraki VPN with Sophos XG310

TAxinte
Here to help

Non Meraki VPN with Sophos XG310

Hello everyone,

 

I've been trying to make a successfull connection between Meraki MX100 (15.44) and Sophos XG310 (18.5.2 MR-2 build380) for more than 1 week.

 

I tried to watch some videos, documentations from Cisco or Sophos but nothing works. The logs are pretty much useless and I'd like some professional advice from you guys.

 

I tried IKEv1 and 2, I tried all the IPsec policies combinations but nothing works.

I was able to see the green light as succesfull connection but I can't ping anything, plus the Sophos from the other side cannot make a connection to my meraki: "parsing IKE message from REMOTE_IP[500] failed"

 

I want to add that I actually have a meraki to meraki VPN active, does it have anything to do with a new non-vpn connection?

 

This is my last config that I left with the "green light" on.

 

TAxinte_1-1643384709050.png

 

TAxinte_2-1643384737969.png

 

 

2 Replies 2
Inderdeep
Kind of a big deal
Kind of a big deal

@TAxinte : I dont know the exact answer but check this thread if it helps

https://community.meraki.com/t5/Security-SD-WAN/Meraki-MX84-to-Sophos-XG-site-to-site-VPN/m-p/50779 

 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com

Thanks for the reply.  I finally solved the issue after weeks of trying.

 

Basically in the "Subnets" field I need to specify both local LAN and the remote LAN subnets. That is not documented on meraki. Sad but glad I managed to do it.

Get notified when there are additional replies to this discussion.