Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP with Comcast Business

I am using Sophos at home and for my business. So, I normally test new versions (or releases) at home first. I have now installed XG at home. While I am still struggling with some RED site to site issues, I also noticed that it keeps dropping the internet from time to time altogether.

My environment at home consists of a small Intel based appliance that should be able to handle the job. Since my entire family are heavy internet users, we opted to go with Comcast Business for reliability and performance. Since we didn't like their modem, we replaced it with a Zoom modem. This environment has worked using UTM software for more than one year now.

From what I can see the modem is providing the external IP using DHCP to the Sophos XG. This mostly works, but it seems to fail if there is a DHCP renewal or other issue. Basically, I have to reset the modem at least once a day since replacing the UTM software with the XG software. I am not sure how the modem communicates a DHCP change to the firewall, but it seems that the UTM software had some extra logic to make this work better.

One difference I noticed is that the XG has a Gateway Name. I can't recall having that on the UTM software, but I am assuming that it is just a logical name used in the software and not something that is used to communicate with the modem. Is that correct? I have currently set that to Comcast.

Do other people see the same issue? Is there anything I can do to improve things? As it is right now, this might become a deal breaker and force me to downgrade again.

One thing I am looking into is that the XG is reporting the hardware interfaces as 100Mbit half-duplex where as I am pretty sure that they are 1GBit full-duplex. That said, I am not sure if observation is related to the issue above.

Any ideas how I can fix this? Thank you!

Cheers,

Jens



This thread was automatically locked due to age.
Parents
  • Hi Jens,

    Take SSH to XG and go to option 4. Device console.

    Execute, tcpdump interface Port#

    Verify whether the DHCP modem is offering the IP to XG.

    Thanks

  • Thank you for your reply!

    Could you please elaborate on what I need to enter to check if the modem is offering the IP? I ran the command as tcpdump interface Port2 (WAN) and it keeps showing me all the traffic going through that port. Is there a way to filter DHCP related traffic? If so, wouldn't that only be visible when there is a renewal?

    Just to clarify: It always fetches a new IP when I power cycle the modem. However, it should do so without that like the UTM did.

    Here is a tcpdump sample of what I am seeing when the connection is down and it should refresh the IP.

    10:30:22.783892 Port1, IN: IP 52.88.3.253.80 > 73.92.124.83.51132: Flags [F.], seq 0, ack 1, win 75, length 0
    10:30:22.783915 Port1, IN: IP 52.88.3.253.80 > 73.92.124.83.51135: Flags [F.], seq 0, ack 1, win 75, length 0
    10:30:22.783924 Port1, IN: IP 52.88.3.253.80 > 73.92.124.83.51131: Flags [F.], seq 0, ack 1, win 75, length 0

    I am also confused because it doesn't always get a new IP when I power cycle the modem. It's almost like the connection occasionally freezes up...

    Cheers,

    Jens

  • Hi Jens,

    Run the TCP dump command when the internet connection is lost and the interface does not fetch IP address.

    Thanks

  • Hi Sachin,

    Here is the (shortened) output:

    console> tcpdump interfac port1
    tcpdump: Starting Packet Dump
    09:14:16.521072 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:16.657680 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:16.885063 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [P.], ack 3269540283, win 64, length 31
    09:14:16.885126 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [F.], seq 31, ack 1, win 64, length 0
    09:14:16.886701 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 31, win 340, length 0
    09:14:16.887155 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:16.919218 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [F.], seq 31, ack 1, win 64, length 0
    09:14:16.919856 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {31:32}], length 0
    09:14:17.099842 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:17.123867 Port1, OUT: IP 73.92.124.83.3997 > 198.41.0.4.53: 39131 A? mzl.la. (24)
    09:14:17.137344 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [FP.], seq 0:31, ack 1, win 64, length 31
    09:14:17.138050 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {0:32}], length 0
    09:14:17.148026 Port1, OUT: IP 73.92.124.83.21655 > 203.205.167.184.5000: Flags [SEW], seq 2835082546, win 8192, options [mss 1460,nop,nop,sackOK], length 0
    09:14:17.149150 Port1, OUT: IP 73.92.124.83.54249 > 118.163.30.162.443: UDP, length 148
    09:14:17.156097 Port1, OUT: IP 73.92.124.83.56713 > 203.205.167.184.443: Flags [S], seq 420104548, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:17.172029 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:17.261478 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:17.261670 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:17.262561 Port1, IN: IP6 fe80::201:5cff:fe84:8a46 > ff02::1: ICMP6, router advertisement, length 144
    09:14:17.310260 Port1, OUT: IP 73.92.124.83.9113 > 192.35.51.30.53: 26429[|domain]
    09:14:17.327071 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:17.511248 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:17.523902 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:17.572265 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [FP.], seq 0:31, ack 1, win 64, length 31
    09:14:17.572945 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {0:32}], length 0
    09:14:17.707879 Port1, OUT: IP 73.92.124.83.61034 > 192.203.230.10.53: 39248 A? ns3.google.com. (32)
    09:14:17.838405 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:17.947897 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:18.152799 Port1, OUT: IP 73.92.124.83.21657 > 203.205.167.183.8080: Flags [SEW], seq 3327472434, win 8192, options [mss 1460,nop,nop,sackOK], length 0
    09:14:18.239838 Port1, OUT: IP 73.92.124.83.53626 > 192.5.5.241.53: 40771 A? goupdate.3g.cn. (32)
    09:14:18.261948 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:18.262163 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:18.305566 Port1, OUT: IP 73.92.124.83.44013 > 75.75.75.75.53: 49738+ A? www.google.com. (32)
    09:14:18.306156 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:18.442212 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [FP.], seq 0:31, ack 1, win 64, length 31
    09:14:18.442890 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {0:32}], length 0
    09:14:18.709469 Port1, IN: IP 52.45.35.167.443 > 73.92.124.83.38564: Flags [FP.], seq 3625975539:3625975570, ack 269144477, win 16616, length 31
    09:14:18.710247 Port1, OUT: IP 73.92.124.83.38564 > 52.45.35.167.443: Flags [R], seq 269144477, win 0, length 0
    09:14:18.713227 Port1, OUT: IP 73.92.124.83.54739 > 75.75.75.75.53: 7792+ A? resolver.1.geo.ctmail.com. (43)
    09:14:18.795851 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:18.842013 Port1, OUT: IP 73.92.124.83.38068 > 104.16.37.226.443: Flags [S], seq 2394877349, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:18.858047 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:18.863331 Port1, OUT: IP 73.92.124.83.5083 > 75.75.75.75.53: 27146+ A? s.tkassets.com. (32)
    09:14:18.865251 Port1, OUT: IP 73.92.124.83.50744 > 75.75.75.75.53: 59382+ A? i.tkassets.com. (32)
    09:14:19.172957 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:19.262255 Port1, OUT: IP 73.92.124.83.33261 > 199.7.83.42.53: 39649 A? e.apsalar.com. (31)
    09:14:19.262321 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:19.262541 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:19.305896 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 124
    09:14:19.380027 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:19.512354 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:19.838486 Port1, OUT: IP 73.92.124.83.38068 > 104.16.37.226.443: Flags [S], seq 2394877349, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:20.146262 Port1, OUT: IP 73.92.124.83.22587 > 192.36.148.17.53: 12556 A? mzl.la. (24)
    09:14:20.180305 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [FP.], seq 0:31, ack 1, win 64, length 31
    09:14:20.180984 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {0:32}], length 0
    09:14:20.191858 Port1, OUT: IP 73.92.124.83.56768 > 192.112.36.4.53: 42491 A? portal.fb.com. (31)
    09:14:20.237169 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.41444: Flags [FP.], seq 3451911668:3451911737, ack 3029053481, win 271, length 69
    09:14:20.261522 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:20.261669 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:20.304236 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 124
    09:14:20.311867 Port1, OUT: IP 73.92.124.83.13003 > 192.33.14.30.53: 38292[|domain]
    09:14:20.495859 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [F.], seq 1, ack 32, win 340, length 0
    09:14:20.592417 Port1, OUT: IP 73.92.124.83.55367 > 74.125.199.188.5228: Flags [P.], ack 250593786, win 1537, options [nop,nop,TS val 3151779 ecr 413562895], length 25
    09:14:20.686509 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:20.730261 Port1, OUT: IP 73.92.124.83.18520 > 128.63.2.53.53: 12263 A? ns3.google.com. (32)
    09:14:20.852456 Port1, IN: IP6 fe80::201:5cff:fe84:8a46 > ff02::1: ICMP6, router advertisement, length 144
    09:14:20.866487 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:20.943865 Port1, OUT: IP 73.92.124.83.52872 > 205.251.199.15.53: 17114 A? peak.wing.sophosxl.net. (40)
    09:14:21.152587 Port1, OUT: IP 73.92.124.83.21657 > 203.205.167.183.8080: Flags [SEW], seq 3327472434, win 8192, options [mss 1460,nop,nop,sackOK], length 0
    09:14:21.261629 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:21.261774 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:21.263963 Port1, OUT: IP 73.92.124.83.47134 > 192.112.36.4.53: 40081 A? goupdate.3g.cn. (32)
    09:14:21.328026 Port1, OUT: IP 73.92.124.83.21848 > 75.75.76.76.53: 24192+ A? www.google.com. (32)
    09:14:21.418597 Port1, OUT: IP 73.92.124.83.53859 > 204.79.197.213.443: Flags [S], seq 4137171953, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:21.596086 Port1, OUT: IP 73.92.124.83.23633 > 192.33.4.12.53: 39800 A? mqtt.c10r.facebook.com. (40)
    09:14:21.735858 Port1, OUT: IP 73.92.124.83.7764 > 75.75.76.76.53: 22697+ A? resolver.1.geo.ctmail.com. (43)
    09:14:21.842473 Port1, OUT: IP 73.92.124.83.38068 > 104.16.37.226.443: Flags [S], seq 2394877349, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:21.887862 Port1, OUT: IP 73.92.124.83.13247 > 75.75.76.76.53: 3338+ A? s.tkassets.com. (32)
    09:14:21.888176 Port1, OUT: IP 73.92.124.83.21746 > 75.75.76.76.53: 15849+ A? i.tkassets.com. (32)
    09:14:22.107171 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:22.262249 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:22.262525 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:22.287839 Port1, OUT: IP 73.92.124.83.47019 > 192.112.36.4.53: 49681 A? e.apsalar.com. (31)
    09:14:22.308146 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 124
    09:14:22.317309 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:22.416068 Port1, OUT: IP 73.92.124.83.53859 > 204.79.197.213.443: Flags [S], seq 4137171953, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:22.616760 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:23.011728 Port1, OUT: IP 73.92.124.83.57200 > 162.125.18.133.443: Flags [.], ack 2903166129, win 1472, length 1440
    09:14:23.147963 Port1, OUT: IP 73.92.124.83.21655 > 203.205.167.184.5000: Flags [S], seq 2835082546, win 8192, options [mss 1460,nop,nop,sackOK], length 0
    09:14:23.170279 Port1, OUT: IP 73.92.124.83.1396 > 192.58.128.30.53: 52454 A? mzl.la. (24)
    09:14:23.191321 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:23.261438 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:23.261604 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:23.334253 Port1, OUT: IP 73.92.124.83.33169 > 192.48.79.30.53: 37132[|domain]
    09:14:23.380483 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:23.432298 Port1, OUT: IP 73.92.124.83.20940 > 75.75.76.76.53: 18442+ A? support.mozilla.org. (37)
    09:14:23.514633 Port1, OUT: IP 73.92.124.83.4780 > 192.58.128.30.53: 29624 A? axigen.us9.list-manage.com. (44)
    09:14:23.532746 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:23.645690 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:23.660205 Port1, IN: IP 31.13.77.6.443 > 73.92.124.83.34412: Flags [FP.], seq 0:31, ack 1, win 64, length 31
    09:14:23.660882 Port1, OUT: IP 73.92.124.83.34412 > 31.13.77.6.443: Flags [.], ack 32, win 340, options [nop,nop,sack 1 {0:32}], length 0
    09:14:23.754204 Port1, OUT: IP 73.92.124.83.31982 > 199.7.83.42.53: 10875 A? ns3.google.com. (32)
    09:14:24.136112 Port1, OUT: IP 73.92.124.83.52894 > 192.198.216.178.3400: Flags [S], seq 374124377, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:24.167425 Port1, OUT: IP 73.92.124.83.39959 > 131.253.34.247.443: Flags [P.], ack 1862181730, win 847, length 117
    09:14:24.261589 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:24.261742 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:24.286254 Port1, OUT: IP 73.92.124.83.54187 > 192.36.148.17.53: 44930 A? goupdate.3g.cn. (32)
    09:14:24.402818 Port1, IN: IP6 fe80::201:5cff:fe84:8a46 > ff02::1: ICMP6, router advertisement, length 144
    09:14:24.404939 Port1, OUT: IP 73.92.124.83.62260 > 75.75.75.75.53: 40190+ A? peak.wing.sophosxl.net. (40)
    09:14:24.405682 Port1, OUT: IP 73.92.124.83.50300 > 204.138.26.166.443: Flags [S], seq 3104841127, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:24.420087 Port1, OUT: IP 73.92.124.83.53859 > 204.79.197.213.443: Flags [S], seq 4137171953, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:24.441908 Port1, OUT: IP 73.92.124.83.49955 > 75.75.75.75.53: 28+ A? google.com. (28)
    09:14:24.464276 Port1, OUT: IP 73.92.124.83.39959 > 131.253.34.247.443: Flags [P.], ack 1, win 847, length 117
    09:14:24.707253 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:24.760437 Port1, OUT: IP 73.92.124.83.39959 > 131.253.34.247.443: Flags [P.], ack 1, win 847, length 117
    09:14:24.893237 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:25.135579 Port1, OUT: IP 73.92.124.83.52894 > 192.198.216.178.3400: Flags [S], seq 374124377, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:25.262649 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:25.262805 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:25.288764 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 108
    09:14:25.311844 Port1, OUT: IP 73.92.124.83.42280 > 199.7.91.13.53: 65341 A? e.apsalar.com. (31)
    09:14:25.352279 Port1, OUT: IP 73.92.124.83.39959 > 131.253.34.247.443: Flags [P.], ack 1, win 847, length 117
    09:14:25.404051 Port1, OUT: IP 73.92.124.83.50300 > 204.138.26.166.443: Flags [S], seq 3104841127, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:25.611447 Port1, IN: IP 162.125.18.133.443 > 73.92.124.83.57200: Flags [.], ack 0, win 360, length 48
    09:14:25.611807 Port1, OUT: IP 73.92.124.83.57200 > 162.125.18.133.443: Flags [.], ack 1, win 1472, options [nop,nop,sack 1 {4294967040:4294967088}], length 0
    09:14:25.675857 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:25.850449 Port1, OUT: IP 73.92.124.83.38068 > 104.16.37.226.443: Flags [S], seq 2394877349, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:26.195857 Port1, OUT: IP 73.92.124.83.16246 > 192.33.4.12.53: 1370 A? mzl.la. (24)
    09:14:26.261491 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:26.261691 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:26.316113 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 124
    09:14:26.336605 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:26.358254 Port1, OUT: IP 73.92.124.83.37706 > 192.54.112.30.53: 32478[|domain]
    09:14:26.540274 Port1, OUT: IP 73.92.124.83.39959 > 131.253.34.247.443: Flags [P.], ack 1, win 847, length 117
    09:14:26.779861 Port1, OUT: IP 73.92.124.83.35916 > 193.0.14.129.53: 59830 A? ns3.google.com. (32)
    09:14:26.868221 Port1, OUT: IP 73.92.124.83.60278 > 31.13.77.5.443: Flags [F.], seq 241729823, ack 3394139323, win 237, length 0
    09:14:27.082218 Port1, OUT: IP 73.92.124.83.60278 > 31.13.77.5.443: Flags [F.], seq 0, ack 1, win 237, length 0
    09:14:27.139575 Port1, OUT: IP 73.92.124.83.52894 > 192.198.216.178.3400: Flags [S], seq 374124377, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:27.147068 Port1, OUT: IP 73.92.124.83.54249 > 118.163.30.162.443: UDP, length 148
    09:14:27.152725 Port1, OUT: IP 73.92.124.83.21657 > 203.205.167.183.8080: Flags [S], seq 3327472434, win 8192, options [mss 1460,nop,nop,sackOK], length 0
    09:14:27.210818 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:27.261743 Port1, IN: IP 192.198.216.178.3400 > 73.92.124.83.3400: UDP, length 92
    09:14:27.261882 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 92
    09:14:27.288098 Port1, OUT: IP 73.92.124.83.60455 > 31.13.77.5.443: Flags [S], seq 1370710159, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:27.298217 Port1, OUT: IP 73.92.124.83.60278 > 31.13.77.5.443: Flags [F.], seq 0, ack 1, win 237, length 0
    09:14:27.310246 Port1, OUT: IP 73.92.124.83.24446 > 202.12.27.33.53: 28114 A? goupdate.3g.cn. (32)
    09:14:27.371957 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:27.408039 Port1, OUT: IP 73.92.124.83.50300 > 204.138.26.166.443: Flags [S], seq 3104841127, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
    09:14:27.418187 Port1, IN: IP 178.22.109.117.65436 > 73.92.124.83.4470: Flags [S], seq 2008035935, win 8192, options [mss 1460,nop,wscale 2,sackOK,TS val 2408870 ecr 0], length 0
    09:14:27.431871 Port1, OUT: IP 73.92.124.83.62088 > 75.75.76.76.53: 23899+ A? peak.wing.sophosxl.net. (40)
    09:14:27.467767 Port1, OUT: IP 73.92.124.83.48531 > 75.75.76.76.53: 8043+ A? google.com. (28)
    09:14:27.552643 Port1, OUT: IP 73.92.124.83.3400 > 192.198.216.178.3400: UDP, length 620
    09:14:27.730231 Port1, OUT: IP 73.92.124.83.60278 > 31.13.77.5.443: Flags [F.], seq 0, ack 1, win 237, length 0
    09:14:27.782304 Port1, OUT: IP 73.92.124.83.46130 > 199.7.91.13.53: 30914 A? resolver.1.geo.ctmail.com. (43)
    09:14:27.782358 Port1, IN: IP6 fe80::201:5cff:fe84:8a46 > ff02::1: ICMP6, router advertisement, length 144

    ...

    Output keeps going. Basically, the system isn't aware that the connection has died and that it needs a new DHCP.

    I don't know how the DHCP notification process works, but when I reset the modem the system picks up a new IP within a minute or so. It doesn't do so without resetting the modem.

    Thanks,

    Jens

  • Hi Jens,

    I guess the WAN is configured on Port2 instead of Port1? Deploy an unmanageable switch between the router and XG, let me know if that helps.

    Thanks

  • Hi Sachin,

    No, I have manually re-assigned the WAN to port1. So, the output shown is for the WAN.

    I have also come to the conclusion that this is a hardware problem. My appliance is using Realtek RTL8111EVL and Realtek RTL8110SC. While the XG identifies all 5 ports provided, I found that port1 and 2 (RTL811EVL) are shown as 100MBit half-duplex instead of 1000MBit full-duplex. Could the half-duplex be the reason for the DHCP problem?

    Anyhow, I also tested the other three ports with even worse results. Port3 and 5 are being identified as 1000MBit full-duplex, but they fail to transport data. Port4 is being identified as 100MBit half-duplex.

    I have raised another threat on the beta feedback forum with my test results and I have also replied to your HCL post. Basically, this hardware works just fine with the latest UTM software. So, it seems that the XG is missing drivers. I am hoping that your statement that the XG is meant to support all existing UTM hardware is true, but I don't know if the development team is aware that drivers are missing.

    Can you reach out to them?

    As a last resort, I installed XG on VMware running on a different machine. DHCP is somewhat working on this machine, but it is slow (up to 1 minute) in comparison to UTM. So, the code around DHCP needs some work!

    On a sidenote: The machine running VMware had a spare Realtek network card and so I figured that I could just use that one as a pass-through card for best performance. Sadly, it only recognized that card as a 10MBit half-duplex card (it is a 1000MBit full-duplex). So, there is something funky with the Realtek driver used by the XG software!

    Hope this helps!

    Cheers,

    Jens

  • Hi Jens,

    If the speed negotiation is the doubted problem then configure the interface to work on Auto Negotiate or anything recommended best settings. To do that take SSH to XG and go to option 4. Device console and execute;

    console> set network interface-speed Port# speed (tab) 

    Alongside, did you try placing an unmanageable switch between the ISP modem and XG?

    Thanks

  • Hi Sachin,

    I haven't tried the console command yet. Is there any difference from setting it manually in the XG configuration? I tried that before and it didn't fix anything.

    I did try putting an unmanaged switch in the middle, but this doesn't seem to change anything either. Was there anything specific you wanted to see when using the switch? I mean it still connects with the incorrect port speeds.

    I am guessing that the XG incorrectly identifies my network cards. This results in the cards working with unpredictable results.

    Maybe your internal team will have some insights on using Realtek cards? Thank you for reaching out to them!

    Cheers,

    Jens

  • Just a quick update on the DHCP problem: I have now installed Sophos XG on a virtual machine and this is doing DHCP with Comcast Business, but it can take up to a minute on renewal at times. On the SG, this used to be almost transparent (~5 seconds average).

    Since nothing else has changed in my environment, there is some problem with the DHCP logic in the XG code.

    Is anybody else using Comcast Business?

    Any feedback from Sophos on this issue?

    Thanks,

    Jens

Reply
  • Just a quick update on the DHCP problem: I have now installed Sophos XG on a virtual machine and this is doing DHCP with Comcast Business, but it can take up to a minute on renewal at times. On the SG, this used to be almost transparent (~5 seconds average).

    Since nothing else has changed in my environment, there is some problem with the DHCP logic in the XG code.

    Is anybody else using Comcast Business?

    Any feedback from Sophos on this issue?

    Thanks,

    Jens

Children
No Data