Skip to content
The XG Series hardware appliances will reach end-of-life (EOL) on March 31, 2025. Click here to see the XG to XGS migration documentation.

Troubleshoot site-to-site SSL VPN

Common configuration errors that prevent Sophos Firewall devices from establishing site-to-site IPsec VPN connections.

Site-to-site SSL VPN connections aren't established after migrating to version 20.0 MR1.

Cause

Firewalls using SFOS 20.0 MR1 won't establish site-to-site SSL VPN connections with firewalls using the following versions:

  • SFOS 18.5 and earlier versions.
  • UTM 9 OS.

Remedy

You can use one of the following options:

  • Use site-to-site IPsec tunnels.
  • Use RED tunnels.
  • Upgrade both firewalls to the latest version.