This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v17.1.0 GA - IPSEC VPN constantly terminates and establish

Hi Sophos,

Device: Sophos XG310
Firmware ver : v17.1.0 GA

 

I've come from firmware version v16.5 mr8 upgraded manually to version v17.1.0 GA.. i've rebuilt all IPSEC VPN profiles and tunnels from scratch since v17 uses different vpn daemon.

I've successfully established connections with the other end, but i've noticed in the SYSTEM LOGS that every 2 mins the tunnel keeps terminating and establishing.

 

From my observation this happens when there is no traffic going in or out in that tunnel, but once i've ran ICMP/PING the logs behaves naturally, there are no termination and establishment going on, but again when the tunnel comes to idle it starts poping it out again, this concerns me that my SYSTEM LOGS will be filled with that unnecessary logs.

 

i've also tried changing my dead peer detection to 900 seconds to see if this affects, but it didn't the interval was still 2 minutes apart

 

is this a normal type of behavior for the new vpn daemon? i didn't experience it from v16.5 mr8.. with or without traffic the VPN will only terminate and establish when it was supposed to.

Regards,
Desmond



This thread was automatically locked due to age.
Parents
  • Hey  

    Welcome to the Sophos Community!

    For context, what remote VPN device is this tunnel connected to? Is there an idle time out setting configured?

  • the VPN tunnels are connected to different firewall brands(cisco asa, sonicwall, fortinet, mikrotik), as far as i know in there end they don't have idle time out setting the other end also is set to RESPOND ONLY.

    based on my observation the side which terminates the connection is the sophos side, im gonna try to disable dead peer detection to verify if that has something connected to that behavior

Reply
  • the VPN tunnels are connected to different firewall brands(cisco asa, sonicwall, fortinet, mikrotik), as far as i know in there end they don't have idle time out setting the other end also is set to RESPOND ONLY.

    based on my observation the side which terminates the connection is the sophos side, im gonna try to disable dead peer detection to verify if that has something connected to that behavior

Children
No Data