Hi Guys,
Strange issue. I have a spoke site connecting to a head office.
The head office is a static IP, but the spoke site is on ADSL with dynamic IP and a ADSL modem. I'm not able to bridge it so the Sophos sits behind this ADSL modem which is doing NAT.
VPN works fine and comes up, however, when the ADSL IP address gets renewed with something else the VPN drops.
Before it was a cisco 800 on this ADSL site and it worked fine with IP address changes, now i have the sophos it drops when the ADSL IP is renewed.
The only way i can fix this is to reboot the sophos! even if i go into the IPSec VPN settings and untick the active check box.. save... then re tick it and hit save.. it cant connect.
When i check, the logs on head office Palo Alto show the remote device is trying to connect. When i check the logs on the Sophos i see "peer did not respond" and "IKE message [xxx] retransmission timed out"
is there something i need to tick or do for Sophos's sitting behind NAT on a dynamic ADSL service?
This thread was automatically locked due to age.