Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Find source for vpn attempt

all,

I am seeing in my logs via the GUI an attempt to build a vpn tunnel.  I suspect I know the source but the log entry doesn't tell me the IP address which is attempting the connection.  here is the only entry that I am seeing:

EST-P1: System did not accept any proposal received. Need to reconfigure the connection on either of the ends

This happens repeatedly but no other messages in the log appear to be related to it.

Also, as a side note, this entire message doesn't appear on the screen.  I have to hover my mouse over the message to read it all.  if you know how to resize the columns in the GUI to see the entire message, I would appreciate the info.

but, the main purpose of my question is to find the source of this attempt.  I have logged in via ssh and ran the "show vpn IPsec-logs" command but it only shows entries relating to my successful IPSEC tunnels.

thanks in advance for any pointers on either of these two issues.



This thread was automatically locked due to age.
  • HI Zane, 

    Sorry to hear about the issue you are facing . As on XG there is no way to resize the column as of now but an idea or feature request is posted in the link below , we request you to support so it may consider the requirements for future releases.

     http://ideas.sophos.com/forums/17359-utm-formerly-asg-feature-requests?query=manage%20log%20viewer%20columns 

    As for the issue for IPSec connection from un-authorized source , you may view in Console and may need to filter check the dumps eg : IPsec works on UDP : 4500 and 500. So you may check

    console > tcpdump 'port 4500 or port 500 . 

    If you have multiple IPsec tunnels , then you may filter out the their WAN addresses.  Additionally.  if you have a list of addresses you may block them by creating a rule in System > Administration > Device Access .

    Thanks and Regards 

    Aditya Patel | Network and Security engineer.