This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Site to Site VPN and firmware V 17 MR8

OK,

I have two XG units.  An XG 135 in my main location, and an XG 105 in a remote office in China.

Both units run : SFOS 16.05.8 MR-8 Firmware

 

I have attempted to update both units to Firmware SFOS 17.0.8 MR-8.  The moment I do this, my IPSEC Site to Site VPN goes down and will not come back up.  I have rebooted both units repeatedly.

 

This is a significant pain in the rear when this happens, because once I lose that VPN connection, I generally have to wait 12 hours or so for someone to get into the China office, use the regular Internet connection to remote into a desktop computer their, connect to the China XG105, and then revert back to the 16 Firmware.

The fact that I can remote into a desktop computer and connect to the firewall as if I was connected to it locally tells me that the unit is working and that the firmware is ok.  

There has to be something wrong with IPSec Site to Site VPN on Firmware 17.  This is the second time I have attempted this.  Several months ago I did the update when I believe the 17 firmware was on MR1 or 2....  Didn't work then either.

So what's different?  I have not modified my VPN setting in any way while going from 16 Firmware to 17 firmware.  I would just assume that it should work.

Thanks in advance for any suggestions or help.

The 17 firmware also throws a services error of something like:  strongswan DEAD

 

Terry

 



This thread was automatically locked due to age.
Parents Reply Children
  • IS that setting only available in the V17 Firmware?  I could not find it in the 16 firmware.  OK, so I just read that KB article, and I am not quite sure I understand.  The KB seems to assume both sides are on V17 I think.

    If I update to V17 on the remote site in China, then I will not have a connection to be able to go and change those settings.  That is the problem I am facing.  It becomes basically a 12 hour or more down time once I update the firmware in China.

    I don't find that acceptable.  I do appreciate the input though.  It feels like I am getting closer to an answer.

    Regards,

    Terry