Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect only connects one time - Strongswan service needs to be killed and restarted to connect again

Hi,

i got an issue with a Windows 11 client. The Sophos Connect client using an existing IPsecVPN connection doesnt connect anymore.

On investigation i figured out, that the client connects one time after reboot - if i disconnect the session and try to connect again, the connection fails. At the Firewall i just can see an log entry with "Timeout" then. The logfile at the client tells "sophos connect befehl konnte nicht an ipsec dienst gesendet werden" (could not send command to ipsec service.

I reinstalled the Sophos Connect Service, deleted the SophosConnect Folder at programmx86, rebootet the machine and installed the client again. This didnt resolve the issue. During deinstallation, the service Strongswan coulnd be stopped.

The process charon-svc.exe needs to be killed in order to be able to stop the strongswan service.

Instead of reboot this also makes able to connect once again - after disconnect, stop strongswan service and during that try of stoping the service the process charon-svc needs to be killed. After restart of the strongswan service the connection can be established once.

Any Idea what needed to be cleaned addtional to get the Connect client again to work properly?

Thanks,

Stefan



This thread was automatically locked due to age.
Parents
  • You need to stop/kill the strongswan service in Windows.

    Pls try this

    1. Open the services applet. Click Start > Programs > Administrative Tools > Services. –or– Click Start > Settings > Control Panel > Administrative Tools > Services.
    2. Click on strongswan service
    3. Stop or kill the strongswan before reinstalling the SCC

    Let me know if this helps.

  • Same problem here after upgrading Sophos Coonect to new build 2.2.90.1104 (under Windows 11 Pro OS)
    One connection (other endpoint: XGS4300 (SFOS 19.5.0 GA-Build197)) is possible. Then the error message "befehl konnte nicht an ipsec-dienst gesendet werden".
    Strongswan service needs to be killed via taskkill /f.
    Then one connection works again.Uninstall not necessary.
    Seems to be a new problem with build 2.2.90.

    Any ideas?

  • We are checking to reproduce the issue. We will keep the thread posted.

Reply Children
No Data