This article will help you connect your Sophos XG with Acreto Ecosystem through the IPsec tunnel.
Firstly, you will need to create a new Gateway device in the Acreto platform. Instructions on how to create a new Gateway are available here.
To simplify testing, add the IP addresses of all interfaces connected to your gateway as Local Networks (you can use /32 prefix for public interface). This will allow you to test connectivity from the gateway through Acreto by using Ping, Traceroute, or similar tools.
To proceed with the Sophos configuration, you will need a few values from an existing committed Acreto Gateway:
All of these may be found within the Gateway details panel - view the below animation for further instruction.
Log in to the Sophos Firewall panel as a user with an administrator role.
From the left side navigation, choose Configure > VPN (1).
Move to the IPsec policies tab (2) and click on the Add button (3) to create a new policy.
Fill the creation form with the following values:
General Settings
Phase1
Click on the Save button to create the policy.
Goto VPN from left side navigator
Select tab IPsec connections and click Add button
Configure VPN with the following setting:
General Settings
Encryption
Local gateway
Remote gateway
Upon saving, the tunnel will try to establish a connection with Acreto, and upon successful connection, the tunnel will come up.
Goto Network from left side navigator
Select tab Network
Click the blue bar on the wan interface. It will unfold the new VPN tunnel interface formed
Click the tunnel interface and add some random IP
Click Save.
Goto Rules and policies from left side navigator
Select tab Firewall rules and click Add firewall rule to add a new firewall rule
Create the firewall rule with values as below
Rule name: to_acreto
Action: Accept
Source Zone: LAN
Source network and devices: Any
During Scheduled time: All the time
Destination zones: Any
Destination network: Any
Services: Any
Verify the connection is going through Acreto.
From any server in the internal subnet, do traceroute
or mtr
and verify if traffic is going through Acreto.
Once the VPN connection is successfully established, all the internal traffic to the internet will be routed through Acreto.