


The first step we need to sync AD with Sophos Firewall. Configure IPSec VPN Client to site Profile.We will configure the IPSec VPN Client to site feature on the Sophos Firewall device, after configuration, we will use the user from AD to connect and when connecting it will receive an IP in the range 10.81.234.5- 10.81.234.55 and gain access to the LAN layer resources. We will have a computer outside the internet to make the IPSec VPN Client to site connection.In the LAN layer, there is also an AD Server with IP 10.145.41.11/24, on this server, an IT OU has been created, in the IT OU there is a Support group, in the Support group there are users as user1,user2,user3.The LAN area of the Sophos Firewall device is configured on port 1 with IP 10.145.41.1/24 and allocates network class 10.145.41.0/24 by DHCP.The Sophos firewall device was connected to the internet through port 2 with WAN IP 192.168.2.103.In this article, techbast will show you how to configure IPSec client to site so that users can access the system remotely with accounts synced from AD.
