Pfsense & Sophos in VM

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

markarr

Active Member
Oct 31, 2013
421
122
43
I'm going to be running plex and some other streaming gear. Can you run link aggregation in sophos to get 2gb links between the networks? I have my San on a separate subnet from my main network. I'd like to run 2gb from my one subnet to the other subnet.
Are you trying to route between the networks? It would work technically but I would not advise it, as you are running all your traffic through the fw engine which adds latency which is not good for a SAN network.
 

mason736

Member
Mar 17, 2013
111
1
18
My .1.1 network is my main network. I have .2.1 as my subnet. I currently have an hp p4300 g2 as my San, with bonded 1gb nics on the .2.1 network. I have an iscsi target to the p4300 from my file server. In the file server, I have a quad port nic, with 2 ports serving the .2.1 iscsi share, and the other 2 serving data to the .1.1 network.

Does that make sense?
 

xbliss

Member
Sep 26, 2015
77
0
6
47
For the UTM it is 50 Ip's
For the new XG version there is no ip limit only 4 cores and 6gb of ram.
I was online trying to download them and was confused between where to download each. I did get one ISO but not sure which of the above two it was. If you can link me to both, I'd like to try them out.
 

JimPhreak

Active Member
Oct 10, 2013
553
55
28
The ssl vpn client they use is a rebraded version of the openvpn client. On ios devices they use the openvpn client with their config. It is under the Remote access section not the site to site. You should be able to get the normal openvpn client working there if you download the config from the user portal.
Are you talking about UTM or XG? I just loaded up the XG virtual appliance and I don't see anything under SSL VPN (Remote Access) that would allow me to setup an OpenVPN client connection. And under SSL (Site-to-Site) it's the same situation as UTM where you must use one of two specified file formats for the config (don't have it in front of me right now or else I'd list them) but you can't use the standard .ovpn file. It seems Sophos still only supports creating site-to-site OpenVPN connections between two Sophos boxes.
 

markarr

Active Member
Oct 31, 2013
421
122
43
Are you talking about UTM or XG? I just loaded up the XG virtual appliance and I don't see anything under SSL VPN (Remote Access) that would allow me to setup an OpenVPN client connection. And under SSL (Site-to-Site) it's the same situation as UTM where you must use one of two specified file formats for the config (don't have it in front of me right now or else I'd list them) but you can't use the standard .ovpn file. It seems Sophos still only supports creating site-to-site OpenVPN connections between two Sophos boxes.
Are you trying to setup a site-to-site with the openvpn or a site-to-client?
 

JimPhreak

Active Member
Oct 10, 2013
553
55
28
Are you trying to setup a site-to-site with the openvpn or a site-to-client?
I need to ability of my firewall to be setup as the client to a VPN service such as AirVPN. I currently have that ability in pfSense and Sophos' lack of support for this feature is what's held me back from using it at home.
 

markarr

Active Member
Oct 31, 2013
421
122
43
I need to ability of my firewall to be setup as the client to a VPN service such as AirVPN. I currently have that ability in pfSense and Sophos' lack of support for this feature is what's held me back from using it at home.
Ah ok, I misunderstood, I thought it was the other way around. You can setup the sophos to be the server and then download the .ovpn files from the client portal
 

JimPhreak

Active Member
Oct 10, 2013
553
55
28
Ah ok, I misunderstood, I thought it was the other way around. You can setup the sophos to be the server and then download the .ovpn files from the client portal
Right that I'm aware of. I use all 3 scenarios on my current pfSense box:
  • Server (pfSense #1) -> Clients (my phones, laptops, etc.)
  • Site-to-Site (pfSense #1 & to pfSense #2)
  • Client (pfSense #1) -> Server (AirVPN servers)
Until Sophos supports all 3 of these scenarios I can't move to them.
 
  • Like
Reactions: xbliss

mason736

Member
Mar 17, 2013
111
1
18
I'm running 2 Sophos VMs in HA on separate ESXi hosts, each host only has one physical NIC and I do everything with VLANs. My modem plugs into my switch and whichever VM is the current primary will use it.
cptbjorn, how did you install Sophos in a VM? The iso I downloaded for XG isn't bootable, so I'm not sure how to pass it to the VM to install.

Thanks
 

cptbjorn

Member
Aug 16, 2013
100
19
18
I haven't used XG but on first glance it looks like you'd want to download one of the virtual appliance versions instead of the one you got.
 

mason736

Member
Mar 17, 2013
111
1
18
I haven't used XG but on first glance it looks like you'd want to download one of the virtual appliance versions instead of the one you got.
Does Sophos allow you to use the home license for the virtual appliance license. I was going to try that, but the home version only has the .iso download available.
 

xbliss

Member
Sep 26, 2015
77
0
6
47
Does Sophos allow you to use the home license for the virtual appliance license. I was going to try that, but the home version only has the .iso download available.
Actually, I have a similar issue - When I first tried to download the Home/ Free versions of UTM & XG, they poppep a "fill in form" on the top of which was a Radio Button allowing me to choose Software vs Virtual Appliance and now when I try I dont see it. So I am wondering where I am goofing up or its stopped now, / it was on a different download from Sophos ?
 

JimPhreak

Active Member
Oct 10, 2013
553
55
28
If you go to Sophos.com and login by clicking on the icon in the top right that looks like a person, you should then be presented with some options under "My Account" on the left hand side. Click on Network Protection and then Download Installers and you should see the following:

 

mason736

Member
Mar 17, 2013
111
1
18
As an FYI,the virtual installer did not work for me. I was able to use the .iso installer for Intel hardware in my c6100
 

modder man

Active Member
Jan 19, 2015
657
84
28
33
I found the OVF deployment but do not know what the default password is. has anyone seen it mentioned somewhere?