Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
This thread was automatically locked due to age.
Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
Just a quick update. I've been working with the GES team, but so far no changes. I was able to upgrade to MR3 and they got the tunnel to establish. It ran for almost a week and then started disconnecting every few hours. High availability completely breaks the tunnel.
The thing that still seems to work, even though it shouldn't, is that if I switch the ipsec profile from Main Mode to Aggressive Mode the tunnel becomes more stable and will only disconnect about once a day rather than every few hours. This is strange because the ASA on the other end is set to Main Mode, and the vpn profile is not even supposed to be compatible with Aggressive Mode. It actually makes the selection list on tunnel profile blank. So this appears to be a definite bug. We're discussing switching back to Cisco. This issue has become a deal breaker for us.
Anyone else had any luck?
My VPN is to Azure and, knock on wood, it's been stable for a couple weeks steady now with only an occasional tunnel pop (seems like a rekey and it never completely breaks traffic). Given the other reports that HA tunnels don't work at all, I'm hesitant to even touch it. As I may have mentioned I had to create a custom IPSEC policy in Azure to align with the config on the XG and even then had to fiddle before it worked reliably. I'm confident Sophos will get their act together on this, otherwise I would have scrapped the XG's and thrown in something else by now.
My VPN is to Azure and, knock on wood, it's been stable for a couple weeks steady now with only an occasional tunnel pop (seems like a rekey and it never completely breaks traffic). Given the other reports that HA tunnels don't work at all, I'm hesitant to even touch it. As I may have mentioned I had to create a custom IPSEC policy in Azure to align with the config on the XG and even then had to fiddle before it worked reliably. I'm confident Sophos will get their act together on this, otherwise I would have scrapped the XG's and thrown in something else by now.