This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC VPN TUNNELS DO NOT WORK ON XG FIREWALL

Dear I have the following scenario.

 

1 Matrix with XG V 17.5 MR12 - 2X DEDICATED STATIC INTERNET LINKS

2 Branches with XG V17.5 MR12 - 2X BROADBAND STATIC INTERNET LINK

1 Branch with XG V18 MR3 - 2X BROADBAND PPOE INTERNET LINK

 

I have an Ipsec Tunnel closed for each Branch initializing to Headquarters.

Constantly and sometimes every day these Tunnels are Down having the need to put a technician from our punishment team to redial the VPN and sometimes no longer closes the connection having to restart the Firewall which is an Absurd, after we restart the Firewall simply all the tunnels reconnect with the Matrix as if by magic.

And the incredible thing that this problem has already been reported by several users in previous versions and was informed in the releasead notes of the release of v18 mr3 that this was solved. More is not solved, we continue with the same problem as always.

 

Worst of all, we exchanged all Sonicwall firewalls for XG sophos and the report is that all VPNS tunnels at the Branches with the Headquarters stood for years without registering any drop when using Sonicwall. It was only implementing Sophos that we started to have problems with VPN Tunnel, and that is because it is a tunnel from XG sophos to XG Sophos wondering if it was a Sophos XG tunnel for another manufacturer what problems would we face if with the same manufacturer closing the VPN the business doesn't work at all.

 

I would like to find a solution for this as we are about to lose the Sophos XG contract due to this instability in the VPN resources.

 

My support case number is: 03340262



This thread was automatically locked due to age.
Parents
  • Hello Fagner,

    Thank you for contacting the Sophos Community!

    To start troubleshooting this, I would 1st recommend you to upgrade the firewalls to v18 and configure the IPsec tunnels as Tunnel Interfaces.

    After you make this change make sure to put the strongswan.log in debug mode, so support can analyze why this might be happening!

    # service strongswan:debug -ds nosync 

    You can turn it off using the same command.

    Regards,

Reply
  • Hello Fagner,

    Thank you for contacting the Sophos Community!

    To start troubleshooting this, I would 1st recommend you to upgrade the firewalls to v18 and configure the IPsec tunnels as Tunnel Interfaces.

    After you make this change make sure to put the strongswan.log in debug mode, so support can analyze why this might be happening!

    # service strongswan:debug -ds nosync 

    You can turn it off using the same command.

    Regards,

Children