This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Gateway 1 - Main ISP keeps getting disconnected, unable to find logs

Hi All,

I would like to seek your assistance regarding our issue.

We have DUAL WAN setup ISP#1 and ISP#2.

Since Thursday, ISP#1 keeps getting disconnected every several hours and it will stay disconnected for 15mins to 20mins.

The problem here is that even though we have a Failover, we still have several Webservers that are not setup for Failover.

So during the ISP#1 downtime, we lost connectivity to several webservers.

I have confirmed that during the 15-20mins downtime, the Internet is still flowing in the Mikrotik Router (ISP#1 router).

I am 100% sure that there is internet in the Mikrotik Router in the duration of the downtime in Sophos.

As I cannot find any meaningful errors in the Sophos logs, I replaced the Ethernet cables from ONT to Mikrotik Router, from Mikrotik to Sophos, and from Sophos to Switch.

I also upgraded to the latest SFOS 17.5.12 MR-12.HF052220.1 yesterday. 

However, this morning, the issue started happening again.

Is there a way to find any meaningful error besides the dgd.log?

I called Sophos Support and spent 2 days chasing Support and a total of 3 hours call but Escalation Engineer told me its an ISP Issue.

I am 100% confirmed that it is NOT an ISP issue as everything is working well in the Mikrotik Router every time ISP#1 went down in Sophos.

If you could just point me to the right direction or logs as to determine what could be causing the problem, I will very much appreciate it.

Thank you.

 


This thread was automatically locked due to age.
Parents
  • Hello Sophos User1499,

    Would it be possible for you to share the Case ID. 

    How are you checking that when the internet goes down on #ISP1 you still have internet connectivity? Have you tried to connect the WAN port that goes to the ISP#1 to a computer when the issue is happening and run a Ping test?

    I take you have changed the Failover rule to ping an IP address beyond the IP of the ISP router?

    Regards,

     

  • @emmosophos,

    I can confirm that the Internet is working on ISP#1.

    I have taken out Sophos Firewall and the internet is working directly from the Mikrotik Router which is the ISP#1.

    Also, from the 6 disconnects yesterday, I found out that there is a 20minute window that Sophos keeps showing that ISP#1 is down from GUI and CLI but when I checked the Public IP on all my devices, it is still getting ISP#1 IP Address. But most of the time, when ISP#1 is showing as down, it will failover to ISP#2, leaving my webservers on ISP#1 down.

    I have told all this to Sophos Escalation Engineer but he keeps insisting that it is an ISP issue which clearly it is NOT an ISP issue.

    I just want to know where to read more meaningful logs to understand why Sophos Firewall keeps disconnecting ISP#1.

    Case#: 9927707

Reply
  • @emmosophos,

    I can confirm that the Internet is working on ISP#1.

    I have taken out Sophos Firewall and the internet is working directly from the Mikrotik Router which is the ISP#1.

    Also, from the 6 disconnects yesterday, I found out that there is a 20minute window that Sophos keeps showing that ISP#1 is down from GUI and CLI but when I checked the Public IP on all my devices, it is still getting ISP#1 IP Address. But most of the time, when ISP#1 is showing as down, it will failover to ISP#2, leaving my webservers on ISP#1 down.

    I have told all this to Sophos Escalation Engineer but he keeps insisting that it is an ISP issue which clearly it is NOT an ISP issue.

    I just want to know where to read more meaningful logs to understand why Sophos Firewall keeps disconnecting ISP#1.

    Case#: 9927707

Children