This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 18.0.0 GA-Build379 Wan Failover not working properly for long lasting udp connections

Hi,

i'm currently running on 18.0.0 GA-Build379, wan failover is working but when the primary gateway is up again some traffic is not terminated on the backup link.

Especially udp 443 traffic (Cisco Anyconnect) keep running on the backup gateway.

I'm not using the configuration from the WAN Failover tab, instead i am using an SD-WAN policy rule with active/backup gateways.

Did anyone have any suggestion?



This thread was automatically locked due to age.
Parents Reply
  • SD-WAN is a Routing Decision for a Session.

    This will be made by the first packet of the session and remain for ever. If another packet comes, it will use the already set connection decision. 

     

    There is a option in WAN Link Manager:

     

    Called: 

     

    It will kill all connections, if the Gateway will comes back up. Therefore the session is considered as "NEW" and will use another gateway. 

     

    This is usable by Backup WAN Interfaces. 

    Backup WAN Interfaces can be used (called) by SD-WAN Rules. 

    So you could use ACTIVE-BACKUP WAN Interfaces and tell XG to destroy everything after failback. 

     

Children