This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN IP was working for 3 weeks then suddenly got blocked

Hi everyone,

 

I am at my wits end on what else to check on what's the cause of the problem. One of my test pc was able to connect to a VPN for 3 weeks straight, I have reviewed the report until last May 18 when the Firewall suddenly started blocking it. I have redacted the VPN IP address for security reasons. 

 

 

I have not made any changes to the firewall that would affect the VPN. I have checked all logs since I started the VPN and it was allowed through the Firewall until it was suddenly blocked.

 

I am hoping someone here can help me with this concern or provide insights on what to check. I was able to fix this issue by Whitelisting the VPN but I wanted to know why it suddenly blocked the VPN after 3 weeks of it working fine.



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Flo,

     

     

    Thanks for your reply. I will try what you advised and will send you a DM for the support access. What I have diagnosed so far was that the VPN login they used changed 2 days prior to the disconnection but still use the same IP. Just give me a day or two to respond back with the support access as I am working on a more critical problem.

     

  • Hi Michael ,

    There must be some changes here.

    Possible Changes, the port used is 443 do you use a VPN portal or connection using 443.

    Ipaddress category was added to the web filter or changes been made to the policy assigned to the firewall. 

     

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • Hi Aditya,

     

     

    Thanks for your Response. No Changes were made to the Firewall. The only change I knew was that the login for their VPN change but still used the same IP address the same IP address which has been working before the incident happened. 

     

    I am trying to trace back the record by using Reports > Custom Reports >Custom web reports. It only gives me the data below. No Port destination. Is there a way to generate a more detailed report? Log Viewer only shows data for a few days and not in the long run. I can no longer get the same data as what I first posted above.