This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN timeout/key negotion after 8 hours

Hello,

 

I have a remote user using SSL vpn connect to our main office Sophos XG virtual appliance. After almost exactly 8 hours it seems that the VPN is re-negotiating keys but fails and the VPN connection dies. This is probably because we are using 2 factor authentication?

 

Is there a way to adjust or disable the re-negotiation of the keys so that this will not happen?

 

Regards

Jacob 



This thread was automatically locked due to age.
Parents Reply Children
  • LuCar Toni said:

     

    That leads to 1-3 OTP Auths per Day in a common scenario, which is annoying but "maybe ok". 

     Assuming you will get the same numbers in Sophos Connect 2.0 ? Could you give this a try? 

    https://community.sophos.com/products/xg-firewall/sfos-eap/sophos-connect-eap/b/announcements/posts/sophos-connect-2-0-early-access

     

     

    That is a bad joke, isn't it? You can't explain you colleagues or even your CEO that he have to reauthenticate just a few times a day, because it's hard coded at the firewall? 

    In times of corona where everyone is reliant to have a stable internet connection. What about Online Meetings, phone calls, file uploads etc. ? "uhm sorry, I have to reauthenticate my vpn client b'cause sophos can't offer an option to adjust the rekey / auth time.  

     

    Yes we could use Sophos Connect 2.0 but only because its was released a few days ago and is still in beta? 

    Anyway what about MacOS Users? 

    I asked the same questions in the Sophos Connect Group, but the only answer is " yeah is at the roadmap". 

     

    Sorry, I really appreciate your support. But this almost the same useless answer which I was get from the regular sophos support as I described before. 

    Sophos should really fix this basic issues! 

  • I could not agree more. Sophos Support is getting more and more worrying. Statments like that are totally not acceptable.
    How can it be that its August and still no solution on a simple issue like this?