Hello,
First of all, I'm sorry for my English.
Secondly, we are currently facing a problem that I can't solve.
Our customer has the following firewall:
- SOPHOS XG125
- The firewall was in SFOS 17.5.9 MR-9 but we changed it to SFOS 17.5.15 MR-15
- 1 remote access SSL VPN built on the basis of Sophos documentation for 3 years
- 3 VPN Ipsec for other sites
- Several firewall rules
For about 1 month it has been experiencing frequent and random disconnections from users in VPNSSL.
I have done the following:
- Looked at reports and diagnostics -> Nothing abnormal was found (hardware, ISP link...)
- Reinstall VPN on client computers -> Same problem
- Checked the certificates -> They are not expired
- Upgrade SFOS 17.5.9 MR-9 to SFOS 17.5.15 MR-15 -> Same issue
- Multiple restarts of the firewall -> Same problem
I can't think of any other solution, has anyone encountered this problem before?
I send my entire logs to Sophos in their ftp server for french support.
Here, you can see logs:
User log (same for each users):
Thu Mar 04 14:11:12 2021 MANAGEMENT: >STATE:1614863472,CONNECTED,SUCCESS,10.81.234.9,X.X.X.X,8443,192.168.1.67,61741
Thu Mar 04 14:16:07 2021 read TCPv4_CLIENT: Connection timed out (WSAETIMEDOUT) (code=10060)
Thu Mar 04 14:16:07 2021 Connection reset, restarting [-1] Thu Mar 04 14:16:07 2021 SIGUSR1[soft,connection-reset] received, process restarting
Thu Mar 04 14:16:07 2021 MANAGEMENT: >STATE:1614863767,RECONNECTING,connection-reset,,,,,
Thu Mar 04 14:16:07 2021 Restart pause, 5 second(s) Thu Mar 04 14:16:12 2021 Socket Buffers: R=[65536->65536] S=[65536->65536]
Thu Mar 04 14:16:12 2021 Attempting to establish TCP connection with [AF_INET]X.X.X.X:8443 [nonblock]
Thu Mar 04 14:16:12 2021 MANAGEMENT: >STATE:1614863772,TCP_CONNECT,,,,,,
Thu Mar 04 14:16:13 2021 TCP connection established with [AF_INET]X.X.X.X:8443
Thu Mar 04 14:16:13 2021 TCPv4_CLIENT link local: [undef] Thu Mar 04 14:16:13 2021 TCPv4_CLIENT link remote: [AF_INET]X.X.X.X:8443
Thu Mar 04 14:16:13 2021 MANAGEMENT: >STATE:1614863773,WAIT,,,,,,
Thu Mar 04 14:16:13 2021 MANAGEMENT: >STATE:1614863773,AUTH,,,,,,
Firewall log in sslvpn.log:
Wed Mar 10 15:32:33 2021 [4692] USER1/::ffff:X.X.X.X Connection reset, restarting [-1]
Wed Mar 10 15:32:33 2021 [4692] USER1/::ffff:X.X.X.X SIGUSR1[soft,connection-reset] received, client-instance restarting
Authentication server 127.0.0.1 gave login response code 2
GARNER: log disconnect event: username=X.X.X.X
Wed Mar 10 15:32:33 2021 [4692] PLUGIN_CALL: POST /lib/openvpn-plugin-utm.so/PLUGIN_CLIENT_DISCONNECT status=0
DELETE 1
COMMIT
ipset v6.14: Element cannot be deleted from the set: it's not added
ipset v6.14: Element cannot be deleted from the set: it's not added
ipset v6.14: Element cannot be deleted from the set: it's not added
Wed Mar 10 15:32:34 2021 [4692] WARNING: Failed running command (--client-disconnect): external program exited with error status: 1
ERROR in csr.log before disconnections:
DEBUG Mar 10 15:32:30 [u2d_dr_installer:1390]: init_db_handle_pl: Initializing DBI DB handle
INFO Mar 10 15:32:30 [u2d_dr_installer:1390]: TRYLOCK: 50
INFO Mar 10 15:32:30 [u2d_dr_installer:1390]: do_get: g_ha_mode
ERROR Mar 10 15:32:30 [u2d_pt_installer:1385]: csc_execve: Child exited with status 244
ERROR Mar 10 15:32:30 [u2d_pt_installer:1385]: log_exec: Failed Command: /bin/nvram qget is_eula
INFO Mar 10 15:32:30 [u2d_pt_installer:1385]: create_act_out_perl_obj: varname=is_eula
INFO Mar 10 15:32:30 [u2d_pt_installer:1385]: create_act_out_perl_obj: is_eula.status=16777204
WARNING Mar 10 15:32:30 [u2d_pt_installer:1385]: action with nofail failed
ERROR Mar 10 15:32:30 [u2d_dr_installer:1390]: csc_execve: Child exited with status 244
ERROR Mar 10 15:32:30 [u2d_dr_installer:1390]: log_exec: Failed Command: /bin/nvram qget is_eula
INFO Mar 10 15:32:30 [u2d_dr_installer:1390]: create_act_out_perl_obj: varname=is_eula
INFO Mar 10 15:32:30 [u2d_dr_installer:1390]: create_act_out_perl_obj: is_eula.status=16777204
WARNING Mar 10 15:32:30 [u2d_dr_installer:1390]: action with nofail failed
DEBUG Mar 10 15:32:30 [listener:1373]: ln_recvfrom: fd '5.UDP.INET.server': 37 bytes are read by listener
DEBUG Mar 10 15:32:30 [listener:1373]: register_request_inet: request from port '46168'
This thread was automatically locked due to age.