This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED 15 failing to connect and Firmware update loops?

So I tried to fit a RED 15 today which is the first I've ever done and was on the phone to Sophos support for about 2 hours trying to get some progress. Initially the RED would get a WAN connection then it would do this sequence with the lights:

1. Green flash - OFF         - OFF         - OFF 
2. Green - Green flash - OFF - OFF
3. Green - Green - Green flash - OFF
4. OFF - OFF - OFF - OFF (presumably got the config and booting up with it?)
5. Green flash - OFF - OFF - OFF
6. Green - Green flash - OFF - OFF
7. Green - Green - Green flash - OFF
8. Red flash - Green - Green flash - OFF

After some various tweaking and log collecting by the Sophos person we did a firmware update on the XG135w and he generated an unlock code to try. Since then it's been stuck in this loop:- https://www.youtube.com/watch?v=MWYcSOJm7Uo

To me it looks like a firmware update is failing but the Sophos person has left it as the port 3410 and 3400 are being blocked by the ISP which is Virgin Media Business and according to their site they dont block those ports but I'm going to have to check this with them tomorrow but I can't see how that would cause what seems to be a firmware update to fail.

Has anyone had this happen before? Does the flashing left to right green lights indicate a firmware update? I'm wondering if the firmware update on the XG is causing the RED to now update which is failing.

Does anyone know if connecting with the console would show any useful information? I'm tempted to buy something like https://www.amazon.co.uk/Console-Cable-Replaces-Laptop-Windows/dp/B01LPQM90G to see if I can get any useful information out of it 

Any suggestions would be great since I think its got the sophos support people a bit stumped at the moment



This thread was automatically locked due to age.
Parents
  • First of all, take a dump on Port 3400 and Port 3410 on the XG. 
    You should see the coming connections from RED. 

    If not: RED is a. not connecting / b. cannot connect because blocking packets. 

    if you see the ports coming, check red.log on XG, if you see something. 

  • So tcpdump doesn't show anything unless I run "telnet xg-public-ip 3400" and type something random and press enter, or if i use "udping xg-public-ip:3140". If i use either of those commands via the same gateway as the RED the XG gets some traffic, but the RED alone makes no attempt to connect to the XG.

    Of note I'm using "tcpdump -i any -vv port 3410 or port 3400" to capture the packets

  • Just to be sure, the hostname, you used for the RED config is reachable from RED site? Did you try your current WAN IP of XG ? 

    Because no packets coming from RED indicates, it cannot connect, is defect, or has a broken config (wrong hostname to connect to). 

    if you checked everything, would suggest to let the RED be replaced by Sophos Support. 

  • The hostname I've set in the RED interface settings is the public IP of the XG.

    I'm inclined to think it's stuck doing a firmware update from the flashing left to right lights, but I have no way to confirm that unless I can connect to the RED's console and see some sort of output of what its doing.

    Just my luck it's probably DOA; I will see what the Support people come back with tomorrow

Reply
  • The hostname I've set in the RED interface settings is the public IP of the XG.

    I'm inclined to think it's stuck doing a firmware update from the flashing left to right lights, but I have no way to confirm that unless I can connect to the RED's console and see some sort of output of what its doing.

    Just my luck it's probably DOA; I will see what the Support people come back with tomorrow

Children
No Data