Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec site-to-site does not automatically reconnect / IKE-Retransmission timeout

Hello,

at a customers site we are experiencing connection issues caused by the provider. Every few days connection gets dropped for 15-30 minutes at night. The provider confirmed the issue but cant resolve it at the moment.

Our sophos xg210 at this site connects via ipsec site-to-site to another xg210 sitting at customers hq. every time the connection gets dropped both SYSTEM logs in Sophos web gui show that the ipsec connection gets terminated and after a while we get e.g. IPsecAZHM-1 - IKE message retransmission timed out (Remote: xx.128.xx.69)
after that the connection stays down and our technicians have to manually initiate the site-to-site connection in the morning (it connects immediately). unfortunately the customer uses this site-to-site connection to access to a terminal server.

Is there a way to configure the IKE Retransmission timeout? Would this even help?

Or do you have any other suggestions to resolve this issue/get the site-to-site to connect automatically again?

btw: others sites are working fine and this did too just until recently 

I also tried to open a case with our vendors support, but they forwarded me to sophos support. there again I cant login because for some maintenance reasons and it tells me to ask the community :)

Thanks 
Daniel

(lurking xg-firewall group for years now, this is my first post)



This thread was automatically locked due to age.
Parents
  • Hi  : Thanks for contacting Sophos community team. Is the XG who is acting as in initiator for IPsec site to site tunnel - what is the key negotiation tries and DPD action? Can you please share snapshot here for reference for policy settings of both the ends. If needed we may tweak the settings based on your current settings.

Reply
  • Hi  : Thanks for contacting Sophos community team. Is the XG who is acting as in initiator for IPsec site to site tunnel - what is the key negotiation tries and DPD action? Can you please share snapshot here for reference for policy settings of both the ends. If needed we may tweak the settings based on your current settings.

Children