This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Other vendor VPN's constantly disconnect when used through a XG Firewall

This seems to be the same issue as https://community.sophos.com/products/xg-firewall/f/network-and-routing/86386/vpns-keep-disconnecting#pi2147=2 which was posted three years ago and had 0 replies.

 

We have a XG 310 firewall with a 500/500 fiber line.  We have had a ongoing issue where other vendor VPN's sometimes will drop randomly.  This is from clients inside the network going to outside VPN's, this is NOT VPN into the XG.  This is affecting almost every other VPN client we have used.  It seems to affect connections using the standard built in Windows VPN, the Cisco AnyConnect client, SonicWall VPN, and others.  The only one we haven't had any issues with is the FortiNet client...it seems pretty stable.  But all the others will just disconnect randomly.  It could work fine for 5 minutes or a hour.  There seems to be no rhyme or reason to it.  But it has been constant for at least a year.  The only solution when it happens is to reconnect or sometimes in the case of the Windows built-in VPN disconnect and then reconnect.  After reconnecting it will work fine again for a random amount of time.

 

If we bypass the XG and hook up directly to our ISP provided router we have no issues with stability.  If we use the same VPN clients from our cell phone hot spots its stable.  If we use the same VPN clients from our home internet it's fine.  But routed through the XG we get random disconnects.  This has been happening with all of firmware 17.*.  We are currently running 18.0.1 MR1-396 and it's made no change.



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi  

    Thank you for reaching out to the Community! 

    Have you noticed any packet drops on the XG firewall when VPN users disconnect? Do you have any IPsec site to site VPN tunnel configured on the XG firewall? 

    Thanks,

  • Haven't noticed anything, even tried watching the firewall log for specific clients and don't see anything other then stuff being allowed.

     

    We do have a couple IPSec site to site tunnels with some of our vendors, 5 in total.   One of them drops and reconnects kind of often (we believe it's a inactivity timer on their side but they don't want to look into it).  The other 4 are stable with no dropping at all for months on end.

     

    But this problem is clients internally connecting to a VPN at a customer location so a client using the built in Windows VPN to connect to a external customer.