Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange issue with MS Always-on-VPN

I've recently moved to Sophos XG (SFOS 19.5.0 GA-Build197) and I've got an odd issue with Always-on-VPN.

My work machine (Windows 10 20H2) uses this to c

onnect to the office but it has stopped working (It was working initially after the move from UTM).

Whether I use wired or wireless my machijne will not connect. The error suggests that fragmentation is the issue but I don't think that's it.

I have tried using two separate phones to hotspot the laptop and it connects without any issues. If I then insert the ethernet cable the WiFi automatically shuts down but connectivity is unbroken. I can switch back and forth from wired to hotspot with no problem but I cannot initiaste the connection while connected behind the XG firewall.

I've looked at some wireshark captures to try to get an inkling of what is happening. and it looks like two response packets are not getting back but I don't know why.

Here's a working connection setup (mobile hotspot) blue is the remote endpoint:

And here's a failing connection setup (green local, blue remote):

You can see that early in the exchange on the working link (line 9 & 10, combined in 11) there are two response packets from the remote endpoint but these are never seen when connected through the XG. (I've captured this process several times). So my laptop never sees the 'Responder Response' while behind the XG.

I've tried turning off SSL/TLS inspection, IPS, I'm not using the proxy. It's as simple and basic as I can make it.

But, as I said, once the connection is established I can connect to the XG with no problems and the connection is solid.

Any ideas, please?



This thread was automatically locked due to age.
Parents Reply Children
  • This is a System rule, you can´t enable/disable ATP on the frontend!
    Enter the shell / device console and check you RAS Server for fragmentation.

    Windows 2019 has fragmentation support enabled by default.

    Check Richard Hicks pages..

    Check your IKA_SA_INIT Packets for fragmentation Support, this can be found in the Payload informations.

  • Sorry, for some reason I didn't see your whole response the first time.

    I did look at Richard's article (amongst several others) that but the endpoint is 2012R2, due for upgrade, and Richard's article says IKEv2 fragmentation is only supported from Server 1803 and above.

    ATP is disabled but I'l have a look at that Bypass article.

    Thanks.

  • Check this article and verifiy for any dropped packages at XG

    https://support.sophos.com/support/s/article/KB-000036858?language=en_US

    I find these method easier than using the log viewer...

  • The bypass had no apparent effect, I'm afraid.

    And the packet capture showed no dropped packets from the remote endpoint. Which suggests to me that the problem is outside my control and down to some change out on the network. Which would explain why it was working and then stopped working for no apparent reason.

    I don't know if it's worth contacting my broadband supplier or not. Generally I don't find the support staff particularly knowledgable about the finer details of networking (and I don't count myself in that number either but I think I have an edge here)  but they should be able to pass on a message.

    Thanks for helping to identify the issue.