Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG <-> XG IPsec tunnel not working anymore

Dear Community. 

We had a working setup between two XG, running on 18.0.5 MR-5-Build 586, that both have a public IPv4. Between we had a working IPSec Tunnel and I could easyly access resources on the different network. It worked until this morning when XG would not pass traffic through the tunnel.

The setup looks like this:

Internal net (branch1) <--> XG1 | WAN <---- Tunnel -----> WAN | XG2 --> Internal net (branch2)

and the tunnel looks like this

XG1 = 10.10.82.1 (xfrm7) <----> 10.10.82.2 (xfrm7) = XG2

There are firewall and static routing rules in place and it did worked until today.

What I currently can do:

Ping from branch 1 to tunnel IP of XG1 but not to tunnel IP of XG2

Ping from branch 2 to tunnel IP of XG2 but not to tunnel IP of XG1

I monitored dropped packages from cli while pinging the other side but there are no dropped packages. I turned off the IPSec tunnel and later on rebooted the XG but without any change. I also tried to reboot XG with old firmware 18.0.4 MR-4 just to make sure, I have no FW problem. Nothing changed. I did not see any errors in the log viewer for Firewall or System facility.

Currently I am lost. Does anyone have a suggestion?

Regards,

Christian



This thread was automatically locked due to age.
Parents
  • To add some more details about the IPSec:

    Sorry - the tunnel interface on the XG2 is not "xfrm7" it is "xfrm1". 

    • Connection Type is "Tunnel interface"
    • Policy is IKEv2
    • Authentication Type is "Preshared Key" ---- and I also changed today the PSK on both XG devices, just to make sure they are equal
    • NAT is turned off
    • XG1 is "respond only", XG2 is "initiate the connection"

    The connection went green and the xfrm7 interfaces are going online, no errors are logged. 

    Note1:

    I checked tcpdump on XG2 and can see that it puts traffic for Branch1 on xfrm1, so it looks like the routing isn't the problem

  • Hello Cwoller

    What is your firewall rule?
    At which position did you place it?

    Regards,

Reply Children